CVE-2023-5869: PostgreSQL vulnerability analysis and mitigation
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.
Source: NVD
Related PostgreSQL vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2025-8715
HIGH
8.8
PostgreSQL
postgresql16-docs
No
Yes
Aug 14, 2025
CVE-2025-8714
HIGH
8.8
PostgreSQL
postgresql:12::postgresql-test-rpm-macros
No
Yes
Aug 14, 2025
CVE-2025-12818
MEDIUM
5.9
PostgreSQL
postgresql:15::postgresql-contrib
No
Yes
Nov 13, 2025
CVE-2025-12817
LOW
3.1
PostgreSQL
postgresql:13::postgresql-contrib
No
Yes
Nov 13, 2025
CVE-2025-8713
LOW
3.1
PostgreSQL
postgresql:16::postgresql-docs
No
Yes
Aug 14, 2025
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.