← Back to feed Search feed

PostgreSQL vulnerabilities

26 entries matching postgresql — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-48031go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 202CRITICAL9.127%ileNVD2026-08-03
CVE-2026-17351The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_quCRITICAL9.437%ileNVD2026-07-31
CVE-2026-17566pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query inCRITICAL9.435%ileNVD2026-07-31
CVE-2026-16503Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces CRITICAL9.116%ileNVD2026-07-31
CVE-2026-17346The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatinHIGH8.736%ileNVD2026-07-31
CVE-2026-45376Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3MEDIUM5.527%ileNVD2026-07-31
CVE-2026-54368CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allowsHIGH8.732%ileNVD2026-07-30
CVE-2026-68563A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and thMEDIUM5.51%ileNVD2026-07-30
CVE-2026-62845Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivMEDIUM4.710%ileNVD2026-07-30
CVE-2026-50736The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscribCRITICAL9.09%ileNVD2026-07-28
CVE-2026-50737When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table'sCRITICAL9.09%ileNVD2026-07-28
CVE-2026-50738A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced aftHIGH7.722%ileNVD2026-07-28
CVE-2026-52888NocoBase: Sensitive Data Exposure via SQL Blacklist BypassMEDIUM6.819%ileGitHub2026-07-28
CVE-2026-50735pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol meMEDIUM6.19%ileNVD2026-07-28
CVE-2026-6473PostgreSQL server undersizes allocations, via integer wraparoundHIGH8.860%ileMicrosoft2026-05-12
CVE-2026-6637PostgreSQL refint allows stack buffer overflow and SQL injectionHIGH8.830%ileMicrosoft2026-05-12
CVE-2026-6477PostgreSQL libpq lo_* functions let server superuser overwrite client stack memoryHIGH8.837%ileMicrosoft2026-05-12
CVE-2026-6475PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choiceHIGH8.825%ileMicrosoft2026-05-12
CVE-2026-6479PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursionHIGH7.538%ileMicrosoft2026-05-12
CVE-2026-6478PostgreSQL discloses MD5-hashed passwords via covert timing channelMEDIUM6.543%ileMicrosoft2026-05-12
CVE-2026-6472PostgreSQL CREATE TYPE does not check multirange schema CREATE privilegeMEDIUM5.46%ileMicrosoft2026-05-12
CVE-2026-6474PostgreSQL timeofday() can disclose portions of server memoryMEDIUM4.312%ileMicrosoft2026-05-12
CVE-2026-6638PostgreSQL REFRESH PUBLICATION allows SQL injection via table nameLOW3.78%ileMicrosoft2026-05-12
FG-IR-26-107Hardcoded symmetric encryption key for PostgresqlUNKNOWNFortinet2026-04-14
CVE-2025-4207PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validationMEDIUM5.949%ileMicrosoft2025-05-13
CVE-2024-4317PostgreSQL pg_stats_ext and pg_stats_ext_exprs lack authorization checksMEDIUM4.350%ileMicrosoft2024-05-14