CVE-2026-73515

Source
https://cve.org/CVERecord?id=CVE-2026-73515
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73515.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73515
Downstream
Published
2026-08-13T15:37:09.289Z
Modified
2026-08-15T11:47:46.843628127Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer
Details

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.

Database specific
{
    "cwe_ids": [
        "CWE-125"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73515.json"
}
References

Affected packages

Git / github.com/postgis/postgis

Affected ranges

Type
GIT
Repo
https://github.com/postgis/postgis
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.7.0beta2"
        }
    ]
}

Affected versions

3.*
3.1.0alpha1
3.1.0alpha2
3.1.0alpha3
3.1.0beta1
3.1.0beta2
3.1.0rc1
3.2.0
3.2.0alpha1
3.2.0beta1
3.2.0beta2
3.2.0beta3
3.2.0rc1
3.3.0alpha1
3.3.0rc1
3.3.0rc2
3.4.0beta1
3.4.0beta2
3.4.0rc1
3.5.0
3.5.0alpha1
3.5.0alpha2
3.5.0beta1
3.5.0rc1
3.6.0beta1
3.6.0rc1
3.6.0rc2
3.7.0alpha1
3.7.0beta1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73515.json"