<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:20:18.479853+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:19009</id>
    <title>ALSA-2026:19009 — Important: postgresql18 security update</title>
    <updated>2026-10-02T19:20:18.496663+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: postgresql18, AlmaLinux:10: postgresql18-contrib, AlmaLinux:10: postgresql18-docs, AlmaLinux:10: postgresql18-plperl, AlmaLinux:10: postgresql18-plpython3, AlmaLinux:10: postgresql18-private-devel, AlmaLinux:10: postgresql18-private-libs, AlmaLinux:10: postgresql18-server, AlmaLinux:10: postgresql18-server-devel, AlmaLinux:10: postgresql18-static and 4 more</p>
<p>PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you'll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.</p>
<p>Security Fix(es):</p>
<p>* postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory (CVE-2026-2007)
  * postgresql: PostgreSQL oidvector discloses a few bytes of memory (CVE-2026-2003)
  * postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code (CVE-2026-2006)
  * postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code (CVE-2026-2004)
  * postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code (CVE-2026-2005)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:19009"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-01724</id>
    <title>bdu:2026-01724</title>
    <updated>2026-10-02T19:20:18.496764+00:00</updated>
    <content>bdu:2026-01724</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-01724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-2007</id>
    <title>BELL-CVE-2026-2007</title>
    <updated>2026-10-02T19:20:18.496794+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: postgresql15, Alpaquita:25: postgresql17, Alpaquita:stream: postgresql18</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-2007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-postgresql-2026-2007</id>
    <title>BIT-postgresql-2026-2007 — PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory</title>
    <updated>2026-10-02T19:20:18.496832+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: postgresql</p>
<p>Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-postgresql-2026-2007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0164</id>
    <title>certfr-2026-avi-0164 — De multiples vulnérabilités ont été découvertes dans PostgreSQL. Elles permettent à un attaquant de provoquer une exécu…</title>
    <updated>2026-10-02T19:20:18.496863+00:00</updated>
    <content>certfr-2026-avi-0164</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0164"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-337521</id>
    <title>EUVD-2026-337521</title>
    <updated>2026-10-02T19:20:18.496886+00:00</updated>
    <content>EUVD-2026-337521</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-337521"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2007</id>
    <title>fkie_cve-2026-2007</title>
    <updated>2026-10-02T19:20:18.496901+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-2007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5pr9-9395-q5gq</id>
    <title>GHSA-5pr9-9395-q5gq</title>
    <updated>2026-10-02T19:20:18.496931+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5pr9-9395-q5gq"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10197-1</id>
    <title>openSUSE-SU-2026:10197-1 — libecpg6-18.2-1.1 on GA media</title>
    <updated>2026-10-02T19:20:18.496952+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libecpg6-18.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10197-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:8756</id>
    <title>RHSA-2026:8756 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-02T19:20:18.496981+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql: improper privilege check during certain RESET ALL operations postgresql: CREATE STATISTICS does not check for schema CREATE privilege postgresql: libpq: libpq undersizes allocations, via integer wraparound postgresql: PostgreSQL oidvector discloses a few bytes of memory postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:8756"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:0585-1</id>
    <title>SUSE-SU-2026:0585-1 — Security update for postgresql18</title>
    <updated>2026-10-02T19:20:18.497021+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for postgresql18</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:0585-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2007</id>
    <title>UBUNTU-CVE-2026-2007</title>
    <updated>2026-10-02T19:20:18.497048+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: postgresql-9.3</p>
<p>Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.  The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.  PostgreSQL 18.1 and 18.0 are affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2007"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0409</id>
    <title>WID-SEC-W-2026-0409 — PostgreSQL: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:20:18.497077+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um Informationen offenzulegen, beliebigen Code auszuführen und nicht näher bezeichnete Angriffe durchzuführen, was möglicherweise zu einer Ausweitung der Berechtigungen führen kann.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0409"/>
  </entry>
</feed>
