CVE-2026-2006
PostgreSQL, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
- CVSS
- 8.8
- EPSS
- 1.08% 61.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.02.12