Integer Wraparound Vulnerability in PostgreSQL by PostgreSQL Global Development Group
CVE-2026-15742

8.8HIGH

What is CVE-2026-15742?

CVE-2026-15742 is an integer wraparound vulnerability found in the fuzzystrmatch extension of PostgreSQL, a widely-used open-source relational database management system. This vulnerability allows an attacker to direct writes to an extensive range of memory addresses by leveraging extreme input values in the SQL functions levenshtein() or levenshtein_less_equal(). With this capability, an attacker can execute arbitrary code as the operating system user that is running the PostgreSQL database. Such a breach could lead to severe security implications for organizations, including unauthorized access to sensitive data and potential complete system control. The vulnerability affects versions prior to PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24, highlighting the necessity for users to upgrade to secure versions to mitigate potential threats.

Potential Impact of CVE-2026-15742

  1. Arbitrary Code Execution: The most critical impact is the ability for an attacker to execute arbitrary code on the server running PostgreSQL. This could allow attackers to install malware, manipulate data, or pivot to other parts of the organization's network.

  2. Data Breach and Integrity Compromise: Exploiting this vulnerability could lead to unauthorized access to sensitive databases. Malicious actors could exfiltrate private data or alter existing records, causing integrity issues which could severely affect business operations and compliance with regulations.

  3. Denial of Service (DoS): By exploiting this vulnerability, an attacker could potentially trigger system instability or crashes, leading to a denial of service. This interruption can have significant operational consequences for organizations relying on PostgreSQL for their databases, resulting in downtime and loss of productivity.

Affected Version(s)

PostgreSQL 18 < 18.6

PostgreSQL 17 < 17.11

PostgreSQL 16 < 16.15

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The PostgreSQL project thanks Ben Morris (Claude and Anthropic Research) for reporting this problem.
.