AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19385

HIGH · CVSS 8.8 EPSS 0.60%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A heap buffer overflow vulnerability in PostgreSQL's pg_dump utility allows an attacker to execute arbitrary code as the operating system user running the tool by exploiting crafted transform lists. This issue affects versions prior to 18.5, 17.11, 16.15, 15.19, and 14.24, and poses a significant risk to database administrators and organizations using these versions. Users of affected PostgreSQL versions should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-19385
Severity
HIGH
CVSS
8.8
EPSS
0.60%

Original NVD Description

Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.