CVE-2023-5870: PostgreSQL vulnerability analysis and mitigation
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.
Source: NVD
Related PostgreSQL vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2025-8715
HIGH
8.8
PostgreSQL
postgresql:16::postgresql-server-devel
No
Yes
Aug 14, 2025
CVE-2025-8714
HIGH
8.8
PostgreSQL
postgresql17-plperl
No
Yes
Aug 14, 2025
CVE-2025-12818
MEDIUM
5.9
PostgreSQL
postgresql13
No
Yes
Nov 13, 2025
CVE-2025-12817
LOW
3.1
PostgreSQL
postgresql16-pltcl
No
Yes
Nov 13, 2025
CVE-2025-8713
LOW
3.1
PostgreSQL
postgresql16-docs-debuginfo
No
Yes
Aug 14, 2025
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.