OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-100387

HIGH · CVSS 8.1 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

pgPointcloud versions up to 1.2.5 are vulnerable to a heap out-of-bounds read issue during WKB deserialization, allowing authenticated database users to access adjacent heap memory. This vulnerability can be exploited by attackers to exfiltrate sensitive data or crash the PostgreSQL backend by supplying malicious pcpatch values. Database administrators and security teams should prioritize patching this vulnerability to mitigate potential data breaches and service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100387
Severity
HIGH
CVSS
8.1
EPSS
0.32%

Original NVD Description

pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.