CVE-2026-2007

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
Configurations

Configuration 1 (hide)

cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

History

30 Jun 2026, 03:18

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:19009 -
  • () https://access.redhat.com/errata/RHSA-2026:8756 -
  • () https://access.redhat.com/security/cve/CVE-2026-2007 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2439320 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2007.json -
CWE CWE-120

17 Jun 2026, 10:29

Type Values Removed Values Added
Summary
  • (es) Desbordamiento de búfer en el heap en PostgreSQL pg_trgm permite a un usuario de base de datos lograr impactos desconocidos mediante una cadena de entrada manipulada. El atacante tiene control limitado sobre los patrones de bytes a escribir, pero no hemos descartado la viabilidad de ataques que conduzcan a la escalada de privilegios. PostgreSQL 18.1 y 18.0 están afectados.

20 Feb 2026, 19:54

Type Values Removed Values Added
First Time Postgresql
Postgresql postgresql
References () https://www.postgresql.org/support/security/CVE-2026-2007/ - () https://www.postgresql.org/support/security/CVE-2026-2007/ - Vendor Advisory
CPE cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

12 Feb 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 14:16

Updated : 2026-07-15 02:19


NVD link : CVE-2026-2007

Mitre link : CVE-2026-2007

CVE.ORG link : CVE-2026-2007


JSON object : View

Products Affected

postgresql

  • postgresql
CWE
CWE-122

Heap-based Buffer Overflow

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')