We found results for “”
CVE-2025-12818
Good to know:
Date: November 13, 2025
Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network peer to cause libpq to undersize an allocation and write out-of-bounds by hundreds of megabytes. This results in a segmentation fault for the application using libpq. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.
Severity Score
Severity Score
Weakness Type (CWE)
Integer Overflow or Wraparound
CWE-190Top Fix
Upgrade Version
Upgrade to version https://github.com/postgres/postgres.git - REL_13_23;https://github.com/postgres/postgres.git - REL_14_20;https://github.com/postgres/postgres.git - REL_15_15;https://github.com/postgres/postgres.git - REL_16_11;https://github.com/postgres/postgres.git - REL_17_7;https://github.com/postgres/postgres.git - REL_18_1
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | HIGH |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | NONE |
| Availability (A): | HIGH |
Vulnerabilities
Projects
Contact Us


