| Bug | bullseye | Description |
|---|
| CVE-2026-19385 | vulnerable | Heap buffer overflow in PostgreSQL pg_dump of long function transform ... |
| CVE-2026-18408 | vulnerable | Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ... |
| CVE-2026-18024 | vulnerable | Buffer over-read in PostgreSQL ascii() SQL function allows a user to d ... |
| CVE-2026-16241 | vulnerable | Integer underflow in PostgreSQL ECPG allows a database server administ ... |
| CVE-2026-16239 | vulnerable | Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user t ... |
| CVE-2026-15742 | vulnerable | Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct ... |
| CVE-2026-15741 | vulnerable | SQL injection in PostgreSQL EXTRACT() deparse allows an object owner t ... |
| CVE-2026-14680 | vulnerable | Type confusion with PostgreSQL "internal" data type arguments allows a ... |
| CVE-2026-14679 | vulnerable | Stack buffer overflow in PostgreSQL argument name matching allows an o ... |
| CVE-2026-14678 | vulnerable | Buffer over-read in PostgreSQL pg_trgm index picksplit function reads ... |
| CVE-2026-14677 | vulnerable | Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl all ... |
| CVE-2026-14673 | vulnerable | Untrusted search path in PostgreSQL amcheck allows a grantee of amchec ... |
| CVE-2026-14671 | vulnerable | Type confusion in PostgreSQL module "refint" allows an object creator ... |
| CVE-2026-14670 | vulnerable | Heap buffer overflow in PostgreSQL plperl return of a tied hash allows ... |
| CVE-2026-14669 | vulnerable | Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the par ... |
| CVE-2026-14668 | vulnerable | Type confusion regarding input of PostgreSQL ctid data type selectivit ... |
| CVE-2026-14666 | vulnerable | Incomplete tracking in PostgreSQL of changes to role membership, role ... |
| CVE-2026-14664 | vulnerable | Heap buffer overflow in PostgreSQL regexp allows the query author to e ... |
| CVE-2026-14663 | vulnerable | Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a use ... |
| CVE-2026-14662 | vulnerable | Integer wraparound in PostgreSQL tsvector and tsquery data type functi ... |
| CVE-2026-6471 | vulnerable | Missing authorization in PostgreSQL logical decoding allows a non-supe ... |
| CVE-2026-6470 | vulnerable | Missing authorization in PostgreSQL DDL commands allows an object crea ... |
| CVE-2026-6469 | vulnerable | Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE co ... |
| CVE-2026-6464 | vulnerable | Untrusted data inclusion in PostgreSQL psql COPY may allow a server ad ... |
| Bug | Description |
|---|
| CVE-2026-16238 | Type confusion in PostgreSQL pg_restore_attribute_stats() allows an ob ... |
| CVE-2026-14681 | Improper enforcement of message integrity in PostgreSQL GSSAPI support ... |
| CVE-2026-14676 | Heap buffer overflow in PostgreSQL pg_stat_statements allows the query ... |
| CVE-2026-14672 | Observable response discrepancy in PostgreSQL SCRAM authentication all ... |
| CVE-2026-6637 | Stack buffer overflow in PostgreSQL module "refint" allows an unprivil ... |
| CVE-2026-6479 | Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an ... |
| CVE-2026-6478 | Covert timing channel in comparison of MD5-hashed password in PostgreS ... |
| CVE-2026-6477 | Use of inherently dangerous function PQfn(..., result_is_int=0, ...) i ... |
| CVE-2026-6475 | Symlink following in PostgreSQL pg_basebackup plain format and in pg_r ... |
| CVE-2026-6474 | Externally-controlled format string in PostgreSQL timeofday() function ... |
| CVE-2026-6473 | Integer wraparound in multiple PostgreSQL server features allows an un ... |
| CVE-2026-6472 | Missing authorization in PostgreSQL CREATE TYPE allows an object creat ... |
| CVE-2026-2007 | Heap buffer overflow in PostgreSQL pg_trgm allows a database user to a ... |
| CVE-2026-2006 | Missing validation of multibyte character length in PostgreSQL text ma ... |
| CVE-2026-2005 | Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provid ... |
| CVE-2026-2004 | Missing validation of type of input in PostgreSQL intarray extension s ... |
| CVE-2026-2003 | Improper validation of type "oidvector" in PostgreSQL allows a databas ... |
| CVE-2025-12818 | Integer wraparound in multiple PostgreSQL libpq client library functio ... |
| CVE-2025-12817 | Missing authorization in PostgreSQL CREATE STATISTICS command allows a ... |
| CVE-2025-8715 | Improper neutralization of newlines in pg_dump in PostgreSQL allows a ... |
| CVE-2025-8714 | Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ... |
| CVE-2025-8713 | PostgreSQL optimizer statistics allow a user to read sampled data with ... |
| CVE-2025-4207 | Buffer over-read in PostgreSQL GB18030 encoding validation allows a da ... |
| CVE-2025-1094 | Improper neutralization of quoting syntax in PostgreSQL libpq function ... |
| CVE-2024-10979 | Incorrect control of environment variables in PostgreSQL PL/Perl allow ... |
| CVE-2024-10978 | Incorrect privilege assignment in PostgreSQL allows a less-privileged ... |
| CVE-2024-10977 | Client use of server error message in PostgreSQL allows a server not t ... |
| CVE-2024-10976 | Incomplete tracking in PostgreSQL of tables with row security allows a ... |
| CVE-2024-7348 | Time-of-check Time-of-use (TOCTOU) race condition in pg_dump in Postgr ... |
| CVE-2024-4317 | Missing authorization in PostgreSQL built-in views pg_stats_ext and pg ... |
| CVE-2024-0985 | Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in Postg ... |
| CVE-2023-39418 | A vulnerability was found in PostgreSQL with the use of the MERGE comm ... |
| CVE-2023-39417 | IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in Po ... |
| CVE-2023-5870 | A flaw was found in PostgreSQL involving the pg_cancel_backend role th ... |
| CVE-2023-5869 | A flaw was found in PostgreSQL that allows authenticated database user ... |
| CVE-2023-5868 | A memory disclosure vulnerability was found in PostgreSQL that allows ... |
| CVE-2023-2455 | Row security policies disregard user ID changes after inlining; Postgr ... |
| CVE-2023-2454 | schema_element defeats protective search_path changes; It was found th ... |
| CVE-2022-41862 | In PostgreSQL, a modified, unauthenticated server can send an untermin ... |
| CVE-2022-2625 | A vulnerability was found in PostgreSQL. This attack requires permissi ... |
| CVE-2022-1552 | A flaw was found in PostgreSQL. There is an issue with incomplete effo ... |
| CVE-2021-32029 | A flaw was found in postgresql. Using an UPDATE ... RETURNING command ... |
| CVE-2021-32028 | A flaw was found in postgresql. Using an INSERT ... ON CONFLICT ... DO ... |
| CVE-2021-32027 | A flaw was found in postgresql in versions before 13.3, before 12.7, b ... |
| CVE-2021-23222 | A man-in-the-middle attacker can inject false responses to the client' ... |
| CVE-2021-23214 | When the server is configured to use trust authentication with a clien ... |
| CVE-2021-20229 | A flaw was found in PostgreSQL in versions before 13.2. This flaw allo ... |
| CVE-2021-3677 | A flaw was found in postgresql. A purpose-crafted query can read arbit ... |
| CVE-2021-3393 | An information leak was discovered in postgresql in versions before 13 ... |
| CVE-2020-25696 | A flaw was found in the psql interactive terminal of PostgreSQL in ver ... |
| CVE-2020-25695 | A flaw was found in PostgreSQL versions before 13.1, before 12.5, befo ... |
| CVE-2020-25694 | A flaw was found in PostgreSQL versions before 13.1, before 12.5, befo ... |
| CVE-2020-21469 | An issue was discovered in PostgreSQL 12.2 allows attackers to cause a ... |