Vulnerability Description
The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by providing a rules table with a classification Type value exceeding the fixed class range. Attackers can craft a malicious rules table entry with an oversized rule type value that is used without bounds checking as an index into an internal output-link table, resulting in an out-of-bounds write.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/postgis/address_standardizer/commit/423570b0dbf6cd9f6fc36de28
- https://github.com/postgis/address_standardizer/pull/3
- https://github.com/postgis/address_standardizer/pull/4
- https://mehmetince.net/part-1-6-systemic-risks-in-the-managed-postgresql-industr
- https://www.vulncheck.com/advisories/postgis-address-standardizer-out-of-bounds-
FAQ
What is CVE-2026-73514?
CVE-2026-73514 is a vulnerability with a CVSS score of 8.8 (HIGH). The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-contr...
How severe is CVE-2026-73514?
CVE-2026-73514 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-73514?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.