CVE-2023-5869: PostgreSQL vulnerability analysis and mitigation
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remote user can trigger the overflow by providing specially crafted data. This enables the execution of arbitrary code on the target system, allowing users to write arbitrary bytes to memory and extensively read the server's memory.
Source: NVD
Related PostgreSQL vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-6464
HIGH
8.1
PostgreSQL
postgresql15
No
Yes
Aug 13, 2026
CVE-2026-73515
HIGH
7.2
PostgreSQL
postgresql18-postgis-client
No
Yes
Aug 13, 2026
CVE-2026-6471
HIGH
7.2
PostgreSQL
cpe:2.3:a:postgresql:postgresql
No
Yes
Aug 13, 2026
CVE-2026-6470
MEDIUM
4.3
PostgreSQL
postgresql-14
No
Yes
Aug 13, 2026
CVE-2026-6469
LOW
3.8
PostgreSQL
postgresql17
No
Yes
Aug 13, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.