Postgresql
46 known vulnerabilities
Top Products
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any
Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and
Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as p
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrar
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary
Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service again
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system u
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the oper
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing ar
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hosti
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT p
Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a tab
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to under
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating
Untrusted search path in PostgreSQL amcheck allows a grantee of amcheck function EXECUTE privilege to execute arbitrary
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence
Type confusion in PostgreSQL module "refint" allows an object creator to execute arbitrary code as the operating system
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as t
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a cal
Incomplete tracking in PostgreSQL of changes to role membership, role attributes, and database ownership allows a query
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user
Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause
pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections
SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table cre
Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as th
Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which cau
Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX
Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover us
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lsee
SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitra
Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite loca
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to un
Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string.
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating syst
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object cre
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory.
Frequently Asked Questions
How many CVEs affect Postgresql?
Postgresql has 46 CVE records in our database, including 0 critical and 29 high severity vulnerabilities.
What are the most severe Postgresql vulnerabilities?
Postgresql has 0 critical severity (CVSS 9.0+) and 29 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Postgresql vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Postgresql products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Postgresql Vulnerabilities
CyberStrike scans your infrastructure for Postgresql vulnerabilities and provides real-time remediation guidance.
Get Started