CVE-2026-2005: PostgreSQL vulnerability analysis and mitigation
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Source: NVD
Related PostgreSQL vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-2006
HIGH
8.8
PostgreSQL
postgresql17-devel
No
Yes
Feb 12, 2026
CVE-2026-2005
HIGH
8.8
PostgreSQL
postgresql18-server
No
Yes
Feb 12, 2026
CVE-2026-2004
HIGH
8.8
PostgreSQL
postgresql:12::postgresql-server-devel
No
Yes
Feb 12, 2026
CVE-2026-2007
HIGH
8.2
PostgreSQL
libpq5
No
Yes
Feb 12, 2026
CVE-2026-3172
HIGH
8.1
PostgreSQL
postgresql18-pgvector
No
Yes
Feb 25, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.