icon

We found results for “

CVE-2025-12817

Good to know:

icon
icon

Date: November 13, 2025

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Severity Score

Severity Score

Weakness Type (CWE)

Missing Authorization

CWE-862

Top Fix

icon

Upgrade Version

Upgrade to version https://github.com/postgres/postgres.git - REL_13_23;https://github.com/postgres/postgres.git - REL_14_20;https://github.com/postgres/postgres.git - REL_15_15;https://github.com/postgres/postgres.git - REL_16_11;https://github.com/postgres/postgres.git - REL_17_7;https://github.com/postgres/postgres.git - REL_18_1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): LOW

Do you need more information?

Contact Us