CVE-2026-2003
Status: AnalyzedMedium (4.3)—
Improper validation of type "oidvector" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.30%
- Percentile among all scored CVEs: 20
- Score date: 10/3/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-1287
References
Raw JSON (NVD)
Show
{
"id": "CVE-2026-2003",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-2003",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-02-12T14:33:29.418479Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 4.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
"affectedData": [
{
"vendor": "n/a",
"product": "PostgreSQL",
"versions": [
{
"status": "affected",
"version": "18",
"lessThan": "18.2",
"versionType": "rpm"
},
{
"status": "affected",
"version": "17",
"lessThan": "17.8",
"versionType": "rpm"
},
{
"status": "affected",
"version": "16",
"lessThan": "16.12",
"versionType": "rpm"
},
{
"status": "affected",
"version": "15",
"lessThan": "15.16",
"versionType": "rpm"
},
{
"status": "affected",
"version": "0",
"lessThan": "14.21",
"versionType": "rpm"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-02-12T14:16:02.067",
"references": [
{
"url": "https://www.postgresql.org/support/security/CVE-2026-2003/",
"tags": [
"Vendor Advisory"
],
"source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007",
"description": [
{
"lang": "en",
"value": "CWE-1287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper validation of type \"oidvector\" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected."
},
{
"lang": "es",
"value": "La validación incorrecta del tipo 'oidvector' en PostgreSQL permite a un usuario de base de datos divulgar unos pocos bytes de memoria del servidor. No hemos descartado la viabilidad de ataques que dispongan la presencia de información confidencial en los bytes divulgados, pero parecen poco probables. Las versiones anteriores a PostgreSQL 18.2, 17.8, 16.12, 15.16 y 14.21 están afectadas."
}
],
"lastModified": "2026-06-17T10:29:59.323",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4BCEAB7B-E4FC-4F9F-A1F9-62EA7DD6D6CC",
"versionEndExcluding": "14.21",
"versionStartIncluding": "14.0"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B408DAF-2DCD-45FE-94EE-BC84947A41C8",
"versionEndExcluding": "15.16",
"versionStartIncluding": "15.0"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6353A59B-FE67-4DD5-B0E6-C10F0D2358D0",
"versionEndExcluding": "16.12",
"versionStartIncluding": "16.0"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E2CCF450-C726-403A-975F-B5717E92A769",
"versionEndExcluding": "17.8",
"versionStartIncluding": "17.0"
},
{
"criteria": "cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6B872502-5316-4E79-8FA1-24E5D8222C39",
"versionEndExcluding": "18.2",
"versionStartIncluding": "18.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"
}