PostGIS is a spatial extension for PostgreSQL that adds geographic information systems capabilities to the database, presenting a narrowly scoped but deeply integrated vulnerability footprint. The recorded issues center on improper input validation in geographic data processing, a characteristic weakness class for spatial libraries handling untrusted coordinate and geometry inputs. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Postgis over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-18359HIGH PostGIS 2.x before 2.3.3, as used with PostgreSQL, allows remote attackers to cause a denial of service via crafted ST_AsX3D function input, as demonstrated by an abnormal server t | Jan 25, 2019 | 7.5 | 27 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Postgis.
Media articles that mention a CVE ID that affects a product developed by Postgis — matched by CVE ID, not by vendor name.