CVE Explorer
CVE-2026-50735
pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copying them, resulting in an out-of-bounds read. A party acting as the publisher for a subscription, for example a non-PostgreSQL endpoint that speaks the pglogical replication protocol, can return crafted messages that cause the subscriber's apply worker to read beyond the bounds of an allocated buffer, disclosing adjacent process memory or crashing the worker.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"affected","product":"pglogical","vendor":"EnterpriseDB","versions":[{"lessThan":"2.4.8","status":"affected","version":"2","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f587c47f6e11d1b6649cd637fed74c9437a3a244a34723a2cf0d74b353037491 · sha256:a0781a20832e8a0d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":6.1,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f587c47f6e11d1b6649cd637fed74c9437a3a244a34723a2cf0d74b353037491 · sha256:a0781a20832e8a0d… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-125","description":"CWE-125 Out-of-bounds Read","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f587c47f6e11d1b6649cd637fed74c9437a3a244a34723a2cf0d74b353037491 · sha256:a0781a20832e8a0d… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.enterprisedb.com/docs/security/advisories/cve202650735/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f587c47f6e11d1b6649cd637fed74c9437a3a244a34723a2cf0d74b353037491 · sha256:a0781a20832e8a0d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.