BIT-postgresql-2026-16238

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/postgresql/BIT-postgresql-2026-16238.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-postgresql-2026-16238
Aliases
  • CVE-2026-16238
Published
2026-08-19T08:52:49.623Z
Modified
2026-08-19T09:45:15.333733858Z
Summary
PostgreSQL type confusion in pg_restore_attribute_stats() executes arbitrary code
Details

Type confusion in PostgreSQL pgrestoreattribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.

Database specific
{
    "cpes": [
        "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / postgresql

Package

Name
postgresql
Purl
pkg:bitnami/postgresql

Severity

  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
18.0.0
Fixed
18.5.0

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/postgresql/BIT-postgresql-2026-16238.json"