<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T18:03:34.382107+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:67280</id>
    <title>ALSA-2026:67280 — Important: postgresql18 security update</title>
    <updated>2026-10-05T18:03:34.642587+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:10: postgresql18, AlmaLinux:10: postgresql18-contrib, AlmaLinux:10: postgresql18-docs, AlmaLinux:10: postgresql18-plperl, AlmaLinux:10: postgresql18-plpython3, AlmaLinux:10: postgresql18-private-devel, AlmaLinux:10: postgresql18-private-libs, AlmaLinux:10: postgresql18-server, AlmaLinux:10: postgresql18-server-devel, AlmaLinux:10: postgresql18-static and 4 more</p>
<p>PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you'll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.</p>
<p>Security Fix(es):</p>
<p>* postgresql: PostgreSQL: SQL injection in pg_createsubscriber allows arbitrary SQL execution as superuser (CVE-2026-6476)
  * postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662)
  * postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump (CVE-2026-18408)
  * postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464)
  * postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471)
  * postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680)
  * postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664)
  * postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677)
  * postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via int…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:67280"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-07099</id>
    <title>bdu:2026-07099</title>
    <updated>2026-10-05T18:03:34.642699+00:00</updated>
    <content>bdu:2026-07099</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-07099"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-6476</id>
    <title>BELL-CVE-2026-6476</title>
    <updated>2026-10-05T18:03:34.642736+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:25: postgresql17, Alpaquita:stream: postgresql18</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-6476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-postgresql-2026-6476</id>
    <title>BIT-postgresql-2026-6476 — PostgreSQL pg_createsubscriber allows SQL injection via subscription name</title>
    <updated>2026-10-05T18:03:34.642771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: postgresql</p>
<p>SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser.  The attack takes effect when pg_createsubscriber next runs.  Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected.  Versions before PostgreSQL 17 are unaffected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-postgresql-2026-6476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0595</id>
    <title>certfr-2026-avi-0595 — De multiples vulnérabilités ont été découvertes dans PostgreSQL. Certaines d'entre elles permettent à un attaquant de p…</title>
    <updated>2026-10-05T18:03:34.642792+00:00</updated>
    <content>certfr-2026-avi-0595</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0595"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-318704</id>
    <title>EUVD-2026-318704</title>
    <updated>2026-10-05T18:03:34.642808+00:00</updated>
    <content>EUVD-2026-318704</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-318704"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-6476</id>
    <title>fkie_cve-2026-6476</title>
    <updated>2026-10-05T18:03:34.642818+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser.  The attack takes effect when pg_createsubscriber next runs.  Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected.  Versions before PostgreSQL 17 are unaffected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-6476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-9crw-q654-rwgr</id>
    <title>GHSA-9crw-q654-rwgr</title>
    <updated>2026-10-05T18:03:34.642839+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser.  The attack takes effect when pg_createsubscriber next runs.  Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected.  Versions before PostgreSQL 17 are unaffected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-9crw-q654-rwgr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-2462</id>
    <title>OESA-2026-2462 — postgresql-17 security update</title>
    <updated>2026-10-05T18:03:34.642854+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: postgresql-17</p>
<p>PostgreSQL client programs

Security Fix(es):</p>
<p>Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to find user-defined types, including extension-defined types.  That is to say, the victim will execute arbitrary SQL functions of the attacker&amp;apos;s choice.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6472)</p>
<p>Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds.  This may execute arbitrary code as the operating system user running the database.  In applications that pass gigabyte-scale user inputs to the relevant database functions, the application input provider may achieve a segmentation fault.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6473)</p>
<p>Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones.  Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.(CVE-2026-6474)</p>
<p>Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite local files, e.g. /var/lib/postgres/.bashrc, that hijack the operating system account.  It will remain the case that starting the server after these commands implicitly trusts the origin superuser, due to feat…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-2462"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10809-1</id>
    <title>openSUSE-SU-2026:10809-1 — postgresql17-17.10-1.1 on GA media</title>
    <updated>2026-10-05T18:03:34.642899+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql17-17.10-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10809-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:22878</id>
    <title>RHSA-2026:22878 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-05T18:03:34.642920+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql: PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege postgresql: integer overflow can cause an undersized allocation and an out-of-bounds write postgresql: PostgreSQL: Information disclosure via externally-controlled format string in timeofday() function postgresql: PostgreSQL: Operating system account hijack via symlink following in pg_basebackup and pg_rewind postgresql: PostgreSQL: SQL injection in pg_createsubscriber allows arbitrary SQL execution as superuser postgresql: PostgreSQL libpq: Buffer overflow allows server superuser to overwrite client stack memory postgresql: PostgreSQL: Credential recovery via covert timing channel in MD5 password comparison postgresql: PostgreSQL: Denial of Service via uncontrolled recursion in SSL/GSS negotiation postgresql: PostgreSQL: Information disclosure via buffer over-read in pg_restore_attribute_stats() postgresql: PostgreSQL: Arbitrary code execution vulnerability in 'refint' module postgresql: PostgreSQL: Arbitrary SQL execution via SQL injection in logical replication</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:22878"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:67280</id>
    <title>RLSA-2026:67280 — Important: postgresql18 security update</title>
    <updated>2026-10-05T18:03:34.642959+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:10: postgresql18</p>
<p>PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you'll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system.  These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection.  The PostgreSQL server can be found in the postgresql-server sub-package.</p>
<p>Security Fix(es):</p>
<p>* postgresql: PostgreSQL: SQL injection in pg_createsubscriber allows arbitrary SQL execution as superuser (CVE-2026-6476)</p>
<p>* postgresql: PostgreSQL: Arbitrary code execution via integer wraparound in tsvector and tsquery functions (CVE-2026-14662)</p>
<p>* postgresql: PostgreSQL: Arbitrary code execution via untrusted data inclusion in pg_dump (CVE-2026-18408)</p>
<p>* postgresql: PostgreSQL psql: Arbitrary command execution via untrusted data in COPY FROM STDIN (CVE-2026-6464)</p>
<p>* postgresql: PostgreSQL: Arbitrary code execution via logical decoding plugin (CVE-2026-6471)</p>
<p>* postgresql: PostgreSQL: Arbitrary code execution via type confusion with "internal" arguments (CVE-2026-14680)</p>
<p>* postgresql: PostgreSQL: Arbitrary code execution via heap buffer overflow in regexp (CVE-2026-14664)</p>
<p>* postgresql: pltcl: plperl: PostgreSQL: Arbitrary code execution in 32-bit pltcl and plperl (CVE-2026-14677)</p>
<p>* postgresql-fuzzystrmatch: PostgreSQL fuzzystrmatch: Arbitrary code execution via integer wraparo…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:67280"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:1946-1</id>
    <title>SUSE-SU-2026:1946-1 — Security update for postgresql18</title>
    <updated>2026-10-05T18:03:34.642999+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for postgresql18</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:1946-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-6476</id>
    <title>UBUNTU-CVE-2026-6476</title>
    <updated>2026-10-05T18:03:34.643020+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: postgresql-9.3, Ubuntu:Pro:16.04:LTS: postgresql-9.5, Ubuntu:Pro:18.04:LTS: postgresql-10, Ubuntu:20.04:LTS: postgresql-12, Ubuntu:22.04:LTS: postgresql-14, Ubuntu:24.04:LTS: postgresql-16, Ubuntu:25.10: postgresql-17, Ubuntu:26.04:LTS: postgresql-18</p>
<p>SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitrary SQL as a superuser.  The attack takes effect when pg_createsubscriber next runs.  Within major versions 17 and 18, minor versions before PostgreSQL 18.4 and 17.10 are affected.  Versions before PostgreSQL 17 are unaffected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-6476"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1544</id>
    <title>WID-SEC-W-2026-1544 — PostgreSQL: Mehrere Schwachstellen</title>
    <updated>2026-10-05T18:03:34.643050+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-1544"/>
  </entry>
</feed>
