- Description
- Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
- Source
- f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
- NVD status
- Modified
- Products
- postgresql
CVSS 3.1
- Type
- Secondary
- Base score
- 8.8
- Impact score
- 5.9
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- Hype score
- Not currently trending
PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVE: CVE-2026-2005 PT ID: PT-2026-7845 Vendor: PostgreSQL Product: PostgreSQL CVSS: 8.8 Credits: Team Xint Code Description: Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute
@ptdbugs
15 Jun 2026
324 Impressions
2 Retweets
7 Likes
2 Bookmarks
0 Replies
0 Quotes
Top 5 Trending CVEs: 1 - CVE-2026-42897 2 - CVE-2026-2005 3 - CVE-2020-25728 4 - CVE-2026-8936 5 - CVE-2026-3910 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W
@CVEShield
12 Jun 2026
100 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes
概念実証(PoC)エクスプロイトが公開されました:20年前のPostgreSQL pgcryptoの脆弱性(CVE-2026-2005)により、完全なスーパーユーザー権限 PoC Exploit Publicly Disclosed: 20-Year-Old PostgreSQL pgcrypto Flaw (CVE-2026-2005) Grants Full
@foxbook
20 May 2026
279 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4BCEAB7B-E4FC-4F9F-A1F9-62EA7DD6D6CC",
"versionEndExcluding": "14.21",
"versionStartIncluding": "14.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"matchCriteriaId": "4B408DAF-2DCD-45FE-94EE-BC84947A41C8",
"versionEndExcluding": "15.16",
"versionStartIncluding": "15.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6353A59B-FE67-4DD5-B0E6-C10F0D2358D0",
"versionEndExcluding": "16.12",
"versionStartIncluding": "16.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E2CCF450-C726-403A-975F-B5717E92A769",
"versionEndExcluding": "17.8",
"versionStartIncluding": "17.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6B872502-5316-4E79-8FA1-24E5D8222C39",
"versionEndExcluding": "18.2",
"versionStartIncluding": "18.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]