Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-2007

32
FAUCET Score

CVE-2026-2007 is a high-severity heap buffer overflow vulnerability in the pg_trgm extension of PostgreSQL versions 18.0 and 18.1. An unauthenticated attacker can exploit this flaw by providing a specially crafted input string, potentially leading to privilege escalation, though the exact impact is still under investigation. The vulnerability has a CVSS score of 8.2 (High) due to its network-based attack vector and low attack complexity, allowing for potential data integrity loss and high availability impact. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 18.0, < 18.2CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.48%
Probability of exploitation in next 30 days
EPSS Percentile
38.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0048 is in the 17th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

beckhoffpatch availablevia llm_extracted
Fixed in: 18.2
View patch
dhis2patch availablevia llm_extracted
Fixed in: 18.2
View patch
fortinetpatch availablevia llm_extracted
Fixed in: 18.2
View patch
miniopatch availablevia llm_extracted
Fixed in: 18.2
View patch
navidromepatch availablevia llm_extracted
Fixed in: 18.2
View patch
netscoutpatch availablevia llm_extracted
Fixed in: 18.2
View patch
new_relicpatch availablevia llm_extracted
Fixed in: 18.2
View patch
nvidiapatch availablevia llm_extracted
Fixed in: 18.2
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql18
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: postgresql18

Vendor Advisories (9)

redhatCVE-2026-2007Important

postgresql: PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory

Feb 12, 2026
fortinetllm-fortinet-e69b38256fa975f4HIGH

PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory

Jan 1, 2026
netscoutllm-netscout-27ccc3eed915b6baHIGH

PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory

new_relicllm-new_relic-4a35e57cdccb75f6HIGH

PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory

dhis2llm-dhis2-626205f345f1e219HIGH

PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory

miniollm-minio-250309c4bf611196HIGH

PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory

navidromellm-navidrome-a316f946fab024b9HIGH

PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory

nvidiallm-nvidia-a959b4cbb62bb81dHIGH

PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory

beckhoffllm-beckhoff-9498e806a8669d96HIGH

PostgreSQL pg_trgm heap buffer overflow writes pattern onto server memory

References

access.redhat.com / errata/RHSA-2026:19009
access.redhat.com / errata/RHSA-2026:8756
access.redhat.com / security/cve/CVE-2026-2007
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-2007.json
postgresql.org / support/security/CVE-2026-2007
Vendor Advisory