CVE-2026-2003

Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:29

Type Values Removed Values Added
Summary
  • (es) La validación incorrecta del tipo 'oidvector' en PostgreSQL permite a un usuario de base de datos divulgar unos pocos bytes de memoria del servidor. No hemos descartado la viabilidad de ataques que dispongan la presencia de información confidencial en los bytes divulgados, pero parecen poco probables. Las versiones anteriores a PostgreSQL 18.2, 17.8, 16.12, 15.16 y 14.21 están afectadas.

20 Feb 2026, 19:53

Type Values Removed Values Added
CPE cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
First Time Postgresql
Postgresql postgresql
References () https://www.postgresql.org/support/security/CVE-2026-2003/ - () https://www.postgresql.org/support/security/CVE-2026-2003/ - Vendor Advisory

12 Feb 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 14:16

Updated : 2026-06-17 10:29


NVD link : CVE-2026-2003

Mitre link : CVE-2026-2003

CVE.ORG link : CVE-2026-2003


JSON object : View

Products Affected

postgresql

  • postgresql
CWE
CWE-1287

Improper Validation of Specified Type of Input