Vulnerability Description
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Postgresql | Postgresql | >= 14.0, < 14.21 |
Related Weaknesses (CWE)
References
- https://www.postgresql.org/support/security/CVE-2026-2003/Vendor Advisory
FAQ
What is CVE-2026-2003?
CVE-2026-2003 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confiden...
How severe is CVE-2026-2003?
CVE-2026-2003 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-2003?
Check the references section above for vendor advisories and patch information. Affected products include: Postgresql Postgresql.