Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-19385

PostgreSQL: pg_dump heap buffer overflow on long function transform lists

Technology

PostgreSQL

CVSS Score

8.8 / 10.0

Affected Versions

Before 18.6, 17.11, 16.15, 15.19 and 14.24 (supported versions only; 13 and older not assessed)

Upstream Fix

18.6; 17.11; 16.15; 15.19; 14.24

Published

August 13, 2026

OSSeva Coverage

Fixed upstream

Description

pg_dump overflowed a heap buffer when dumping a function with a long transform list, so an object creator could craft a transform list that runs arbitrary code as the operating system user running pg_dump. Scored 8.8 by PostgreSQL as the CNA. Fixed in 18.6, 17.11, 16.15, 15.19 and 14.24.

Upstream record: NVD · CVE.org

Is your PostgreSQL deployment affected?

If you're running Before 18.6, 17.11, 16.15, 15.19 and 14.24 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.