CVE-2026-2007
published 2026-02-12CVE-2026-2007: Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over…
PriorityP349high8.2CVSS 3.1
AVNACLPRNUINSUCNILAH
EPSS
0.48%
38.3th percentile
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | postgresql-13 | < postgresql-18 18.2-1 (forky) | postgresql-18 18.2-1 (forky) |
| debian | postgresql-15 | < postgresql-18 18.2-1 (forky) | postgresql-18 18.2-1 (forky) |
| debian | postgresql-17 | < postgresql-18 18.2-1 (forky) | postgresql-18 18.2-1 (forky) |
| debian | postgresql-18 | < postgresql-18 18.2-1 (forky) | postgresql-18 18.2-1 (forky) |
| postgresql | postgresql | >= 18 < 18.2 | 18.2 |
| postgresql | postgresql | >= 18.0 < 18.2 | 18.2 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
osv8.2HIGH
vendor_debian8.2LOW
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
PostgreSQL 18.0/18.1 pg_trgm heap-based overflow (Nessus ID 298888 / WID-SEC-2026-0409)
vuldb·2026-07-01·CVSS 8.2
CVE-2026-2007 [HIGH] PostgreSQL 18.0/18.1 pg_trgm heap-based overflow (Nessus ID 298888 / WID-SEC-2026-0409)
A vulnerability classified as critical has been found in PostgreSQL 18.0/18.1. This affects an unknown function of the component pg_trgm. Performing a manipulation results in heap-based buffer overflow.
This vulnerability is identified as CVE-2026-2007. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
OSV
CVE-2026-2007: Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string
osv·2026-02-12·CVSS 8.2
CVE-2026-2007 [HIGH] CVE-2026-2007: Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
GHSA
GHSA-5pr9-9395-q5gq: Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string
ghsa_unreviewed·2026-02-12
CVE-2026-2007 [HIGH] CWE-122 GHSA-5pr9-9395-q5gq: Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
Red Hat
postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
vendor_redhat·2026-02-12·CVSS 8.2
CVE-2026-2007 [HIGH] CWE-120 postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
A heap based buffer overflow has been discovered in postgresql. This heap buffer overflow is in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation.
Mitigation: Mitigation for this issue is eit
Debian
CVE-2026-2007: postgresql-13 - Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unk...
vendor_debian·2026·CVSS 8.2
CVE-2026-2007 [HIGH] CVE-2026-2007: postgresql-13 - Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unk...
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
Scope: local
bullseye: resolved
Citrix
Citrix Security Bulletin CTX112964
vendor_citrix·CVSS 10.0
CVE-2007-2850 [CRITICAL] Citrix Security Bulletin CTX112964
Citrix Security Bulletin CTX112964
CVE References: CVE-2007-2850, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX113543
vendor_citrix·CVSS 5.0
CVE-2007-3625 [MEDIUM] Citrix Security Bulletin CTX113543
Citrix Security Bulletin CTX113543
CVE References: CVE-2007-3625, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX113817
vendor_citrix·CVSS 7.6
CVE-2007-4017 [HIGH] Citrix Security Bulletin CTX113817
Citrix Security Bulletin CTX113817
CVE References: CVE-2007-4017, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX115281
vendor_citrix·CVSS 2.1
CVE-2007-6267 [LOW] Citrix Security Bulletin CTX115281
Citrix Security Bulletin CTX115281
CVE References: CVE-2007-6267, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX113814
vendor_citrix·CVSS 5.0
CVE-2007-0011 [MEDIUM] Citrix Security Bulletin CTX113814
Citrix Security Bulletin CTX113814
CVE References: CVE-2007-0011, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX113816
vendor_citrix·CVSS 6.8
CVE-2007-4018 [MEDIUM] Citrix Security Bulletin CTX113816
Citrix Security Bulletin CTX113816
CVE References: CVE-2007-4018, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX113815
vendor_citrix·CVSS 4.3
CVE-2007-3679 [MEDIUM] Citrix Security Bulletin CTX113815
Citrix Security Bulletin CTX113815
CVE References: CVE-2007-3679, CVE-2007-4013, CVE-2007-4016, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX112803
vendor_citrix·CVSS 5.0
CVE-2007-0011 [MEDIUM] Citrix Security Bulletin CTX112803
Citrix Security Bulletin CTX112803
CVE References: CVE-2007-0011, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX115283
vendor_citrix·CVSS 4.3
CVE-2007-6477 [MEDIUM] Citrix Security Bulletin CTX115283
Citrix Security Bulletin CTX115283
CVE References: CVE-2007-6477, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Red Hat
CVE-2007-2026: The gnu regular expression code in file 4
vendor_redhat·CVSS 7.8
CVE-2007-2026 [HIGH] CVE-2007-2026: The gnu regular expression code in file 4
The gnu regular expression code in file 4.20 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted document with a large number of line feed characters, which is not well handled by OS/2 REXX regular expressions that use wildcards, as originally reported for AMaViS.
Statement: Not vulnerable. These issues did not affect the versions of file as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
Citrix
Citrix Security Bulletin CTX114028
vendor_citrix·CVSS 4.3
CVE-2007-3679 [MEDIUM] Citrix Security Bulletin CTX114028
Citrix Security Bulletin CTX114028
CVE References: CVE-2007-3679, CVE-2007-4013, CVE-2007-4016, CVE-2007-4017, CVE-2007-4018, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX112589
vendor_citrix·CVSS 9.3
CVE-2007-1196 [CRITICAL] Citrix Security Bulletin CTX112589
Citrix Security Bulletin CTX112589
CVE References: CVE-2007-1196, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
Citrix
Citrix Security Bulletin CTX111686
vendor_citrix·CVSS 7.2
CVE-2007-0444 [HIGH] Citrix Security Bulletin CTX111686
Citrix Security Bulletin CTX111686
CVE References: CVE-2007-0444, CVE-2025-12101, CVE-2025-62626, CVE-2026-23554, CVE-2026-3055, CVE-2026-4368, CVE-2026-4397
Affected Products: Citrix ADM, Citrix Hypervisor, Citrix Virtual Apps and Desktops, Endpoint Management, NetScaler ADC, NetScaler Gateway, XenServer
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-2004 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-2004 [HIGH] CVE-2026-2004 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2004 :
PostgreSQL vulnerability analysis and mitigation
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Source : NVD
## 8.8
Score
Published February 12, 2026
Severity HIGH
CNA Score 8.8
High-profile Vulnerability Yes
Affected Technologies
PostgreSQL
Rocky Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 14.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
postgresql15-test-rpm-macros
postgresql18-pltcl
Sources
Alma
Wiz
CVE-2026-3172 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-3172 [HIGH] CVE-2026-3172 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-3172 :
PostgreSQL vulnerability analysis and mitigation
Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.
Source : NVD
## 8.1
Score
Published February 25, 2026
Severity HIGH
CNA Score 8.1
Affected Technologies
PostgreSQL
pgVector
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
postgresql15-pgvector
postgresql16-pgvector
Sources
NVD
Debian 13 Severity MEDIUM No Fix Added at: Mar 02, 2026
Debian 14 Severity HIGH Has Fix Added at: Mar 02, 2026
Echo Severity HIGH No Fix Adde
Wiz
CVE-2026-2003 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-2003 [MEDIUM] CVE-2026-2003 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2003 :
PostgreSQL vulnerability analysis and mitigation
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Source : NVD
## 4.3
Score
Published February 12, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
PostgreSQL
Rocky Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
postgresql16
postgresql:12::postgre
Wiz
CVE-2026-2005 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-2005 [HIGH] CVE-2026-2005 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2005 :
PostgreSQL vulnerability analysis and mitigation
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Source : NVD
## 8.8
Score
Published February 12, 2026
Severity HIGH
CNA Score 8.8
High-profile Vulnerability Yes
Affected Technologies
PostgreSQL
Rocky Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 7.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
postgresql:12::postgresql-test
postgresql16-private-libs-debuginfo
Sources
AlmaLinux 8 Severity HIGH Has Fix Adde
Wiz
CVE-2026-2006 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-2006 [HIGH] CVE-2026-2006 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2006 :
PostgreSQL vulnerability analysis and mitigation
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Source : NVD
## 8.8
Score
Published February 12, 2026
Severity HIGH
CNA Score 8.8
High-profile Vulnerability Yes
Affected Technologies
PostgreSQL
Rocky Linux
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.7
Exploitation Probability (EPSS) N/A
Affected packages and libraries
postgresql17-co
Wiz
CVE-2026-2007 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-2007 [HIGH] CVE-2026-2007 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-2007 :
PostgreSQL vulnerability analysis and mitigation
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
Source : NVD
## 8.2
Score
Published February 12, 2026
Severity HIGH
CNA Score 8.2
Affected Technologies
PostgreSQL
Linux openSUSE
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
postgresql
libecpg6
Sources
Alpine 3.20, 3.21, 3.22,
Bugzilla
CVE-2026-2007 postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
bugzilla·2026-02-12·CVSS 8.2
CVE-2026-2007 [HIGH] CVE-2026-2007 postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
CVE-2026-2007 postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:19009 https://access.redhat.com/errata/RHSA-2026:19009
https://www.postgresql.org/support/security/CVE-2026-2007/https://access.redhat.com/errata/RHSA-2026:19009https://access.redhat.com/errata/RHSA-2026:8756https://access.redhat.com/security/cve/CVE-2026-2007https://bugzilla.redhat.com/show_bug.cgi?id=2439320https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2007.json
2026-02-12
Published