Heap Buffer Overflow in PostgreSQL pgcrypto Affects Multiple Versions
CVE-2026-2005
Key Information:
- Vendor
PostgreSQL
- Status
- Vendor
- CVE Published:
- 12 February 2026
Badges
What is CVE-2026-2005?
The pgcrypto module in PostgreSQL contains a heap buffer overflow vulnerability that can be exploited by a ciphertext provider. This vulnerability allows an attacker to execute arbitrary code within the context of the operating system user that is running the database. Importantly, this affects various versions of PostgreSQL prior to the latest releases, making it crucial for users to upgrade to the patched versions to safeguard against potential exploits.
Affected Version(s)
PostgreSQL 18 < 18.2
PostgreSQL 17 < 17.8
PostgreSQL 16 < 16.12
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved