cbcvebase.
CVE-2026-2007
published 2026-02-12

CVE-2026-2007: Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over…

PriorityP349high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
0.48%
38.3th percentile
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianpostgresql-13< postgresql-18 18.2-1 (forky)postgresql-18 18.2-1 (forky)
debianpostgresql-15< postgresql-18 18.2-1 (forky)postgresql-18 18.2-1 (forky)
debianpostgresql-17< postgresql-18 18.2-1 (forky)postgresql-18 18.2-1 (forky)
debianpostgresql-18< postgresql-18 18.2-1 (forky)postgresql-18 18.2-1 (forky)
postgresqlpostgresql>= 18 < 18.218.2
postgresqlpostgresql>= 18.0 < 18.218.2

CVSS provenance

nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
osv8.2HIGH
vendor_debian8.2LOW
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.