<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 23:46:35 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:19009 — Important: postgresql18 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:19009</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: postgresql18, AlmaLinux:10: postgresql18-contrib, AlmaLinux:10: postgresql18-docs, AlmaLinux:10: postgresql18-plperl, AlmaLinux:10: postgresql18-plpython3, AlmaLinux:10: postgresql18-private-devel, AlmaLinux:10: postgresql18-private-libs, AlmaLinux:10: postgresql18-server, AlmaLinux:10: postgresql18-server-devel, AlmaLinux:10: postgresql18-static and 4 more&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you&amp;#39;ll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory (CVE-2026-2007)
  * postgresql: PostgreSQL oidvector discloses a few bytes of memory (CVE-2026-2003)
  * postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code (CVE-2026-2006)
  * postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code (CVE-2026-2004)
  * postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code (CVE-2026-2005)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: postgresql18, AlmaLinux:10: postgresql18-contrib, AlmaLinux:10: postgresql18-docs, AlmaLinux:10: postgresql18-plperl, AlmaLinux:10: postgresql18-plpython3, AlmaLinux:10: postgresql18-private-devel, AlmaLinux:10: postgresql18-private-libs, AlmaLinux:10: postgresql18-server, AlmaLinux:10: postgresql18-server-devel, AlmaLinux:10: postgresql18-static and 4 more&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you&amp;#39;ll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory (CVE-2026-2007)
  * postgresql: PostgreSQL oidvector discloses a few bytes of memory (CVE-2026-2003)
  * postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code (CVE-2026-2006)
  * postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code (CVE-2026-2004)
  * postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code (CVE-2026-2005)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:19009</guid>
    </item>
    <item>
      <title>bdu:2026-01727</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01727</link>
      <description>bdu:2026-01727</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01727</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-2004</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-2004</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: postgresql15, Alpaquita:25: postgresql17, Alpaquita:stream: postgresql18&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: postgresql15, Alpaquita:25: postgresql17, Alpaquita:stream: postgresql18&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-2004</guid>
    </item>
    <item>
      <title>BIT-postgresql-2026-2004 — PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code</title>
      <link>https://cve.radiocsirt.org/vuln/bit-postgresql-2026-2004</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: postgresql&lt;/p&gt;
&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: postgresql&lt;/p&gt;
&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-postgresql-2026-2004</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0164 — De multiples vulnérabilités ont été découvertes dans PostgreSQL. Elles permettent à un attaquant de provoquer une exécu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0164</link>
      <description>certfr-2026-avi-0164</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0164</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-DT63161 — Security fix for CVE-2026-2004 applied in: postgresql17 17.8-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-dt63161</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql17&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the postgresql17 package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql17&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the postgresql17 package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-dt63161</guid>
    </item>
    <item>
      <title>EUVD-2026-337524</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337524</link>
      <description>EUVD-2026-337524</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337524</guid>
    </item>
    <item>
      <title>fkie_cve-2026-2004</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2004</link>
      <description>&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-2004</guid>
    </item>
    <item>
      <title>GHSA-qw3h-8vxv-jf6c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qw3h-8vxv-jf6c</link>
      <description>&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qw3h-8vxv-jf6c</guid>
    </item>
    <item>
      <title>NCSC-2026-0321 — Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0321</link>
      <description>NCSC-2026-0321</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0321</guid>
    </item>
    <item>
      <title>OESA-2026-1493 — postgresql security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1493</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: postgresql&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS).
The base postgresql package contains the client programs that you&amp;amp;amp;apos;ll need to
access a PostgreSQL DBMS server, as well as HTML documentation for the whole
system.  These client programs can be located on the same machine as the
PostgreSQL server, or on a remote machine that accesses a PostgreSQL server
over a network connection.  The PostgreSQL server can be found in the
postgresql-server sub-package.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Improper validation of type &amp;amp;quot;oidvector&amp;amp;quot; in PostgreSQL allows a database user to disclose a few bytes of server memory.  We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2003)&lt;/p&gt;
&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2004)&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2005)&lt;/p&gt;
&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulatio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: postgresql&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS).
The base postgresql package contains the client programs that you&amp;amp;amp;apos;ll need to
access a PostgreSQL DBMS server, as well as HTML documentation for the whole
system.  These client programs can be located on the same machine as the
PostgreSQL server, or on a remote machine that accesses a PostgreSQL server
over a network connection.  The PostgreSQL server can be found in the
postgresql-server sub-package.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Improper validation of type &amp;amp;quot;oidvector&amp;amp;quot; in PostgreSQL allows a database user to disclose a few bytes of server memory.  We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2003)&lt;/p&gt;
&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2004)&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2005)&lt;/p&gt;
&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulatio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1493</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10190-1 — postgresql14-14.21-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10190-1</link>
      <description>&lt;p&gt;postgresql14-14.21-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql14-14.21-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10190-1</guid>
    </item>
    <item>
      <title>RHSA-2026:4074 — Red Hat Security Advisory: postgresql:13 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:4074</link>
      <description>&lt;p&gt;postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:4074</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0585-1 — Security update for postgresql18</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0585-1</link>
      <description>&lt;p&gt;Security update for postgresql18&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for postgresql18&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0585-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-2004</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2004</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: postgresql-9.3, Ubuntu:Pro:16.04:LTS: postgresql-9.5, Ubuntu:Pro:18.04:LTS: postgresql-10, Ubuntu:20.04:LTS: postgresql-12, Ubuntu:22.04:LTS: postgresql-14, Ubuntu:24.04:LTS: postgresql-16, Ubuntu:25.10: postgresql-17&lt;/p&gt;
&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: postgresql-9.3, Ubuntu:Pro:16.04:LTS: postgresql-9.5, Ubuntu:Pro:18.04:LTS: postgresql-10, Ubuntu:20.04:LTS: postgresql-12, Ubuntu:22.04:LTS: postgresql-14, Ubuntu:24.04:LTS: postgresql-16, Ubuntu:25.10: postgresql-17&lt;/p&gt;
&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2004</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0409 — PostgreSQL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0409</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um Informationen offenzulegen, beliebigen Code auszuführen und nicht näher bezeichnete Angriffe durchzuführen, was möglicherweise zu einer Ausweitung der Berechtigungen führen kann.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um Informationen offenzulegen, beliebigen Code auszuführen und nicht näher bezeichnete Angriffe durchzuführen, was möglicherweise zu einer Ausweitung der Berechtigungen führen kann.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0409</guid>
    </item>
  </channel>
</rss>
