CVE Explorer
CVE-2026-2003
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"PostgreSQL","vendor":"n/a","versions":[{"lessThan":"18.2","status":"affected","version":"18","versionType":"rpm"},{"lessThan":"17.8","status":"affected","version":"17","versionType":"rpm"},{"lessThan":"16.12","status":"affected","version":"16","versionType":"rpm"},{"lessThan":"15.16","status":"affected","version":"15","versionType":"rpm"},{"lessThan":"14.21","status":"affected","version":"0","versionType":"rpm"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ed7457ff33981a1b7300e9e96c834360c84bd04980611bd1d7e84744a3b13a71 · sha256:5b13e4fcc2a19cee… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":4.3,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ed7457ff33981a1b7300e9e96c834360c84bd04980611bd1d7e84744a3b13a71 · sha256:5b13e4fcc2a19cee… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-1287","description":"Improper Validation of Specified Type of Input","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ed7457ff33981a1b7300e9e96c834360c84bd04980611bd1d7e84744a3b13a71 · sha256:5b13e4fcc2a19cee… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.postgresql.org/support/security/CVE-2026-2003/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ed7457ff33981a1b7300e9e96c834360c84bd04980611bd1d7e84744a3b13a71 · sha256:5b13e4fcc2a19cee… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.