Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-2006

PostgreSQL: missing multibyte character length validation allows code execution

Technology

PostgreSQL

CVSS Score

8.8 / 10.0

Affected Versions

Before 18.2, 17.8, 16.12, 15.16 and 14.21 (supported versions only; 13 and older not assessed)

Upstream Fix

18.2; 17.8; 16.12; 15.16; 14.21

Published

February 12, 2026

OSSeva Coverage

Fixed upstream

Description

Text manipulation code did not validate multibyte character lengths, so a database user could issue crafted queries that overrun a buffer, which is enough to run arbitrary code as the operating system user running the database. Scored 8.8 by PostgreSQL as the CNA. Fixed in 18.2, 17.8, 16.12, 15.16 and 14.21.

Upstream record: NVD · CVE.org

Is your PostgreSQL deployment affected?

If you're running Before 18.2, 17.8, 16.12, 15.16 and 14.21 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.