CVE-2026-2007

Public on 2026-02-12
Modified on 2026-02-13
Description
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core postgresql Not Affected
Amazon Linux 2 - Postgresql14 Extra postgresql Not Affected
Amazon Linux 2023 postgresql15 Not Affected
Amazon Linux 2023 postgresql16 Not Affected
Amazon Linux 2023 postgresql17 Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H