CVE-2026-2006
PostgreSQL: missing multibyte character length validation allows code execution
Technology
PostgreSQL
CVSS Score
8.8 / 10.0
Affected Versions
Before 18.2, 17.8, 16.12, 15.16 and 14.21 (supported versions only; 13 and older not assessed)
Upstream Fix
18.2; 17.8; 16.12; 15.16; 14.21
Published
February 12, 2026
OSSeva Coverage
Fixed upstream
Description
Text manipulation code did not validate multibyte character lengths, so a database user could issue crafted queries that overrun a buffer, which is enough to run arbitrary code as the operating system user running the database. Scored 8.8 by PostgreSQL as the CNA. Fixed in 18.2, 17.8, 16.12, 15.16 and 14.21.
Is your PostgreSQL deployment affected?
If you're running Before 18.2, 17.8, 16.12, 15.16 and 14.21 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.