CVE-2026-2006

Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
References
Link Resource
https://www.postgresql.org/support/security/CVE-2026-2006/ Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:19009
https://access.redhat.com/errata/RHSA-2026:19010
https://access.redhat.com/errata/RHSA-2026:3730
https://access.redhat.com/errata/RHSA-2026:3887
https://access.redhat.com/errata/RHSA-2026:3896
https://access.redhat.com/errata/RHSA-2026:4024
https://access.redhat.com/errata/RHSA-2026:4059
https://access.redhat.com/errata/RHSA-2026:4063
https://access.redhat.com/errata/RHSA-2026:4064
https://access.redhat.com/errata/RHSA-2026:4074
https://access.redhat.com/errata/RHSA-2026:4075
https://access.redhat.com/errata/RHSA-2026:4110
https://access.redhat.com/errata/RHSA-2026:4254
https://access.redhat.com/errata/RHSA-2026:4441
https://access.redhat.com/errata/RHSA-2026:4475
https://access.redhat.com/errata/RHSA-2026:4504
https://access.redhat.com/errata/RHSA-2026:4505
https://access.redhat.com/errata/RHSA-2026:4506
https://access.redhat.com/errata/RHSA-2026:4509
https://access.redhat.com/errata/RHSA-2026:4515
https://access.redhat.com/errata/RHSA-2026:4516
https://access.redhat.com/errata/RHSA-2026:4518
https://access.redhat.com/errata/RHSA-2026:4524
https://access.redhat.com/errata/RHSA-2026:4528
https://access.redhat.com/errata/RHSA-2026:4544
https://access.redhat.com/errata/RHSA-2026:4546
https://access.redhat.com/errata/RHSA-2026:4547
https://access.redhat.com/errata/RHSA-2026:4548
https://access.redhat.com/errata/RHSA-2026:4943
https://access.redhat.com/errata/RHSA-2026:8756
https://access.redhat.com/security/cve/CVE-2026-2006
https://bugzilla.redhat.com/show_bug.cgi?id=2439324
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2006.json
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-12 14:16

Updated : 2026-07-15 02:19


NVD link : CVE-2026-2006

Mitre link : CVE-2026-2006

CVE.ORG link : CVE-2026-2006


JSON object : View

Products Affected

postgresql

  • postgresql
CWE
CWE-129

Improper Validation of Array Index

CWE-1285

Improper Validation of Specified Index, Position, or Offset in Input