BIT-postgresql-2026-2007

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/postgresql/BIT-postgresql-2026-2007.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-postgresql-2026-2007
Aliases
Published
2026-02-16T16:03:46.313Z
Modified
2026-02-16T17:11:26.893766Z
Summary
PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
Details

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.

Database specific
{
    "severity": "High",
    "cpes": [
        "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / postgresql

Package

Name
postgresql
Purl
pkg:bitnami/postgresql

Severity

  • 8.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
18.0.0
Fixed
18.2.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/postgresql/BIT-postgresql-2026-2007.json"