Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
PoC: cve-2026-2005
CVE-2026-2005 — PostgreSQL pgcrypto heap overflow RCE exploit
PoC: CVE-2026-2005
PoC for CVE-2026-2005
PoC: CVE-2026-2005
PoC for CVE-2026-2005 — heap buffer overflow in PostgreSQL pgcrypto (pgp_pub_decrypt). Oversized PGP session key bypasses bounds check in pgp-pubdec.c. Affects < 17.8 / 16.12 / 15.16 / 14.21 / 18.2.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free