CVE-2023-5869: PostgreSQL vulnerability analysis and mitigation
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.
Source: NVD
Related PostgreSQL vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-6638
HIGH
8.8
PostgreSQL
postgresql17-private-libs
No
Yes
May 14, 2026
CVE-2026-6637
HIGH
8.8
PostgreSQL
postgresql:16::pgvector.src
No
Yes
May 14, 2026
CVE-2026-6479
HIGH
7.5
PostgreSQL
postgresql:12::postgresql-server-devel
No
Yes
May 14, 2026
CVE-2026-6478
MEDIUM
6.5
PostgreSQL
postgresql-docs-debuginfo
No
Yes
May 14, 2026
CVE-2026-6575
MEDIUM
4.3
PostgreSQL
postgresql16
No
Yes
May 14, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.