CVE-2026-2007 is a high-severity heap buffer overflow vulnerability in the pg_trgm extension of PostgreSQL versions 18.0 and 18.1. An unauthenticated attacker can exploit this flaw by providing a specially crafted input string, potentially leading to privilege escalation, though the exact impact is still under investigation. The vulnerability has a CVSS score of 8.2 (High) due to its network-based attack vector and low attack complexity, allowing for potential data integrity loss and high availability impact. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.0, < 18.2CPE matchmatch criteria | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
Feb 12, 2026PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
Jan 1, 2026PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory
PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory