CVE-2026-2003: PostgreSQL vulnerability analysis and mitigation
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Source: NVD
Related PostgreSQL vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-2006
HIGH
8.8
PostgreSQL
postgresql17-devel
No
Yes
Feb 12, 2026
CVE-2026-2005
HIGH
8.8
PostgreSQL
postgresql18-server
No
Yes
Feb 12, 2026
CVE-2026-2004
HIGH
8.8
PostgreSQL
postgresql:12::postgresql-server-devel
No
Yes
Feb 12, 2026
CVE-2026-2007
HIGH
8.2
PostgreSQL
libpq5
No
Yes
Feb 12, 2026
CVE-2026-3172
HIGH
8.1
PostgreSQL
postgresql18-pgvector
No
Yes
Feb 25, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.