icon

We found results for “

CVE-2025-12818

Good to know:

icon
icon

Date: November 13, 2025

Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Severity Score

Severity Score

Weakness Type (CWE)

Integer Overflow or Wraparound

CWE-190

Top Fix

icon

Upgrade Version

Upgrade to version https://github.com/postgres/postgres.git - REL_13_23;https://github.com/postgres/postgres.git - REL_14_20;https://github.com/postgres/postgres.git - REL_15_15;https://github.com/postgres/postgres.git - REL_16_11;https://github.com/postgres/postgres.git - REL_17_7;https://github.com/postgres/postgres.git - REL_18_1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us