Out-of-bounds read in PostgreSQL - CVE-2026-18024
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the ascii() SQL function when processing a crafted text value. A remote user can supply a crafted text value to disclose sensitive information.
Successful exploitation can disclose up to 3 bytes after the end of a specific allocation.
Affected software
Debian Linux
postgresql-17 (Debian package)
How to mitigate CVE-2026-18024
postgresql-17 (Debian package) - update to 17.11-0+deb13u1