← Back to CVE List
CVE-2026-15742NVD
Vulnerability Summary
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVSS v3.1 Base Metrics — Score 8.8 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Postgresql Postgresql >= 14.0 and < 14.24
- Postgresql Postgresql >= 15.0 and < 15.19
- Postgresql Postgresql >= 16.0 and < 16.15
- Postgresql Postgresql >= 17.0 and < 17.11
- Postgresql Postgresql >= 18.0 and < 18.5
- Postgresql Postgresql 14.24
- Postgresql Postgresql 15.19
- Postgresql Postgresql 16.15
- Postgresql Postgresql 17.11
- Postgresql Postgresql 18.5