<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 19:08:25 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:19009 — Important: postgresql18 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:19009</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: postgresql18, AlmaLinux:10: postgresql18-contrib, AlmaLinux:10: postgresql18-docs, AlmaLinux:10: postgresql18-plperl, AlmaLinux:10: postgresql18-plpython3, AlmaLinux:10: postgresql18-private-devel, AlmaLinux:10: postgresql18-private-libs, AlmaLinux:10: postgresql18-server, AlmaLinux:10: postgresql18-server-devel, AlmaLinux:10: postgresql18-static and 4 more&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you&amp;#39;ll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory (CVE-2026-2007)
  * postgresql: PostgreSQL oidvector discloses a few bytes of memory (CVE-2026-2003)
  * postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code (CVE-2026-2006)
  * postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code (CVE-2026-2004)
  * postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code (CVE-2026-2005)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:10: postgresql18, AlmaLinux:10: postgresql18-contrib, AlmaLinux:10: postgresql18-docs, AlmaLinux:10: postgresql18-plperl, AlmaLinux:10: postgresql18-plpython3, AlmaLinux:10: postgresql18-private-devel, AlmaLinux:10: postgresql18-private-libs, AlmaLinux:10: postgresql18-server, AlmaLinux:10: postgresql18-server-devel, AlmaLinux:10: postgresql18-static and 4 more&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS). The base postgresql package contains the client programs that you&amp;#39;ll need to access a PostgreSQL DBMS server, as well as HTML documentation for the whole system. These client programs can be located on the same machine as the PostgreSQL server, or on a remote machine that accesses a PostgreSQL server over a network connection. The PostgreSQL server can be found in the postgresql-server sub-package.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory (CVE-2026-2007)
  * postgresql: PostgreSQL oidvector discloses a few bytes of memory (CVE-2026-2003)
  * postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code (CVE-2026-2006)
  * postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code (CVE-2026-2004)
  * postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code (CVE-2026-2005)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:19009</guid>
    </item>
    <item>
      <title>bdu:2026-01723</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01723</link>
      <description>bdu:2026-01723</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01723</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-2006</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-2006</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: postgresql15, Alpaquita:25: postgresql17, Alpaquita:stream: postgresql18&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: postgresql15, Alpaquita:25: postgresql17, Alpaquita:stream: postgresql18&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-2006</guid>
    </item>
    <item>
      <title>BIT-postgresql-2026-2006 — PostgreSQL missing validation of multibyte character length executes arbitrary code</title>
      <link>https://cve.radiocsirt.org/vuln/bit-postgresql-2026-2006</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: postgresql&lt;/p&gt;
&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun.  That suffices to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: postgresql&lt;/p&gt;
&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun.  That suffices to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-postgresql-2026-2006</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0164 — De multiples vulnérabilités ont été découvertes dans PostgreSQL. Elles permettent à un attaquant de provoquer une exécu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0164</link>
      <description>certfr-2026-avi-0164</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0164</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-NZ43393 — Security fixes in postgresql 17.8-r0</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-nz43393</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql&lt;/p&gt;
&lt;p&gt;Package postgresql version 17.8-r0 fixes 4 vulnerabilities: CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: postgresql&lt;/p&gt;
&lt;p&gt;Package postgresql version 17.8-r0 fixes 4 vulnerabilities: CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-nz43393</guid>
    </item>
    <item>
      <title>EUVD-2026-337522</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337522</link>
      <description>EUVD-2026-337522</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337522</guid>
    </item>
    <item>
      <title>fkie_cve-2026-2006</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-2006</link>
      <description>&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun.  That suffices to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun.  That suffices to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-2006</guid>
    </item>
    <item>
      <title>GHSA-mq5v-x68w-mc4f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mq5v-x68w-mc4f</link>
      <description>&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun.  That suffices to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun.  That suffices to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mq5v-x68w-mc4f</guid>
    </item>
    <item>
      <title>NCSC-2026-0321 — Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0321</link>
      <description>NCSC-2026-0321</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0321</guid>
    </item>
    <item>
      <title>OESA-2026-1493 — postgresql security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1493</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: postgresql&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS).
The base postgresql package contains the client programs that you&amp;amp;amp;apos;ll need to
access a PostgreSQL DBMS server, as well as HTML documentation for the whole
system.  These client programs can be located on the same machine as the
PostgreSQL server, or on a remote machine that accesses a PostgreSQL server
over a network connection.  The PostgreSQL server can be found in the
postgresql-server sub-package.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Improper validation of type &amp;amp;quot;oidvector&amp;amp;quot; in PostgreSQL allows a database user to disclose a few bytes of server memory.  We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2003)&lt;/p&gt;
&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2004)&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2005)&lt;/p&gt;
&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulatio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS: postgresql&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced Object-Relational database management system (DBMS).
The base postgresql package contains the client programs that you&amp;amp;amp;apos;ll need to
access a PostgreSQL DBMS server, as well as HTML documentation for the whole
system.  These client programs can be located on the same machine as the
PostgreSQL server, or on a remote machine that accesses a PostgreSQL server
over a network connection.  The PostgreSQL server can be found in the
postgresql-server sub-package.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;Improper validation of type &amp;amp;quot;oidvector&amp;amp;quot; in PostgreSQL allows a database user to disclose a few bytes of server memory.  We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2003)&lt;/p&gt;
&lt;p&gt;Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2004)&lt;/p&gt;
&lt;p&gt;Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.(CVE-2026-2005)&lt;/p&gt;
&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulatio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1493</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10190-1 — postgresql14-14.21-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10190-1</link>
      <description>&lt;p&gt;postgresql14-14.21-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql14-14.21-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10190-1</guid>
    </item>
    <item>
      <title>RHSA-2026:4074 — Red Hat Security Advisory: postgresql:13 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:4074</link>
      <description>&lt;p&gt;postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql: PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code postgresql: PostgreSQL pgcrypto heap buffer overflow executes arbitrary code postgresql: PostgreSQL missing validation of multibyte character length executes arbitrary code&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:4074</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0585-1 — Security update for postgresql18</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0585-1</link>
      <description>&lt;p&gt;Security update for postgresql18&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for postgresql18&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0585-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-2006</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2006</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: postgresql-9.3, Ubuntu:Pro:16.04:LTS: postgresql-9.5, Ubuntu:Pro:18.04:LTS: postgresql-10, Ubuntu:20.04:LTS: postgresql-12, Ubuntu:22.04:LTS: postgresql-14, Ubuntu:24.04:LTS: postgresql-16, Ubuntu:25.10: postgresql-17&lt;/p&gt;
&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun.  That suffices to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: postgresql-9.3, Ubuntu:Pro:16.04:LTS: postgresql-9.5, Ubuntu:Pro:18.04:LTS: postgresql-10, Ubuntu:20.04:LTS: postgresql-12, Ubuntu:22.04:LTS: postgresql-14, Ubuntu:24.04:LTS: postgresql-16, Ubuntu:25.10: postgresql-17&lt;/p&gt;
&lt;p&gt;Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun.  That suffices to execute arbitrary code as the operating system user running the database.  Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-2006</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0409 — PostgreSQL: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0409</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um Informationen offenzulegen, beliebigen Code auszuführen und nicht näher bezeichnete Angriffe durchzuführen, was möglicherweise zu einer Ausweitung der Berechtigungen führen kann.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in PostgreSQL ausnutzen, um Informationen offenzulegen, beliebigen Code auszuführen und nicht näher bezeichnete Angriffe durchzuführen, was möglicherweise zu einer Ausweitung der Berechtigungen führen kann.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0409</guid>
    </item>
  </channel>
</rss>
