CVE-2026-2005
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
- Affected products
- Linuxmint, Postgresql, Red Os, Rocky Linux, Ubuntu
- Postgresql
- < 14.21, 15.16, 16.12, 17.8, 18.2
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 1.2% (65th percentile)
- Weakness
- CWE-122, CWE-120
- NVD status
- Modified
- Published
- 2026-02-12
CVE-2026-2005 at NVD
4 known exploits for CVE-2026-2005
Proof-of-concept code and exploit modules indexed by Sploitus