Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-1058

30
FAUCET Score

CVE-2018-1058 is a high-severity vulnerability affecting PostgreSQL versions 9.3 through 10, allowing an authenticated attacker to execute arbitrary code with superuser privileges within the database by manipulating query behavior for other users. The CVSS score of 8.8 indicates a critical risk, with a low attack complexity and high impact on confidentiality, integrity, and availability. While the Exploit Prediction Scoring System (EPSS) suggests a high likelihood of exploitation, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and no evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 9.3, < 9.3.22CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 9.4, < 9.4.17CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 9.5, < 9.5.12CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 9.6, < 9.6.8CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*
>= 10.0, < 10.3CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
13.18%
Probability of exploitation in next 30 days
EPSS Percentile
96.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.1318 is in the 95th percentile among its peer group of 17,822 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (26)

redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-0:5.9.6.5-3.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-amazon-smartstate-0:5.9.6.5-2.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-appliance-0:5.9.6.5-1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: cfme-gemset-0:5.9.6.5-2.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: dbus-api-service-0:1.0.1-3.1.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: httpd-configmap-generator-0:0.2.2-1.2.el7cf
View patch
redhatpatch availablevia redhat_api
Product: CloudForms Management Engine 5.9Fixed in: postgresql96-0:9.6.10-1PGDG.el7at
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-postgresql95-postgresql-0:9.5.14-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: rh-postgresql96-postgresql-0:9.6.10-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSFixed in: rh-postgresql95-postgresql-0:9.5.14-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSFixed in: rh-postgresql96-postgresql-0:9.6.10-1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-postgresql95-postgresql-0:9.5.14-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: rh-postgresql96-postgresql-0:9.6.10-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSFixed in: rh-postgresql95-postgresql-0:9.5.14-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUSFixed in: rh-postgresql96-postgresql-0:9.6.10-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-postgresql95-postgresql-0:9.5.14-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: rh-postgresql96-postgresql-0:9.6.10-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-postgresql95-postgresql-0:9.5.14-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: rh-postgresql96-postgresql-0:9.6.10-1.el7
View patch
redhatend of lifevia redhat_api
Product: CloudForms Management Engine 5Fixed in: postgresql94
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: postgresql
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: postgresql84
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: postgresql
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: postgresql
redhatend of lifevia redhat_api
Product: Red Hat Satellite 5Fixed in: postgresql95-postgresql
redhatend of lifevia redhat_api
Product: Red Hat Software CollectionsFixed in: rh-postgresql94-postgresql

Vendor Advisories (1)

redhatCVE-2018-1058Moderate

postgresql: Uncontrolled search path element in pg_dump and other client applications

Mar 1, 2018

References

access.redhat.com / errata/RHSA-2018:2511
Third Party Advisory
access.redhat.com / errata/RHSA-2018:2566
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3816
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
usn.ubuntu.com / 3589-1
Third Party Advisory
postgresql.org / about/news/1834
Vendor Advisory
securityfocus.com / bid/103221
Third Party AdvisoryVDB Entry