Heap Buffer Overflow Vulnerability in PostgreSQL pg_dump
CVE-2026-19385
8.8HIGH
What is CVE-2026-19385?
A heap buffer overflow vulnerability exists in PostgreSQL's pg_dump utility, specifically when handling long function transform lists. This flaw enables an object creator to craft a malicious transform list that can manipulate memory allocation, leading to arbitrary code execution as the operating system user executing pg_dump. This vulnerability affects several versions of PostgreSQL prior to the specified security updates, making systems running outdated versions potentially susceptible to exploitation.
Affected Version(s)
PostgreSQL 18 < 18.5
PostgreSQL 17 < 17.11
PostgreSQL 16 < 16.15