← All tracked CVEs
Updated 03:00
not yet fixed but still within SLA
82 open
| CVE | Status | Severity | Summary | Release | Clock started | Deadline |
|---|---|---|---|---|---|---|
| Open | High | SQL injection in PostgreSQL EXTRACT() deparse allows superuser execution via hostile object definitions | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL 18<18.5 pg_restore_attribute_stats type confusion allows RCE as database OS user | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL ctid selectivity estimator type confusion leaks 4-byte memory-derived values via non-ctid input | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL logical decoding auth flaw lets REPLICATION users execute arbitrary code as server OS account | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL 'internal' type confusion lets any user execute arbitrary code; affects <18.5,17.11,16.15,15.19,14.24 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | Type confusion in PostgreSQL portal/cursor lifecycle enables OS-level code execution; pre-18.5, 17.11, 16.15, 15.19, 14.24 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL 32-bit pltcl/plperl integer wraparound causes undersized allocation, OOB write, RCE | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL plperl tied-hash return heap overflow enables RCE as database OS user | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL tsvector/tsquery integer wraparound allows OOB write, potential RCE by unprivileged users | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | Heap buffer overflow in PostgreSQL to_char(timestamptz) via long timezone abbreviation enables RCE | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL refint type confusion allows arbitrary OS code execution; no CVE; affects pre-18.5/17.11/16.15/15.19/14.24 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL pg_dump heap buffer overflow in transform lists enables RCE; versions <18.5/17.11/16.15/15.19/14.24 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | psql COPY FROM STDIN pre-input error executes data lines as commands | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | Integer wraparound RCE in PostgreSQL fuzzystrmatch via levenshtein/less_equal before 18.5/17.11/16.15/15.19/14.24 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL stack buffer overflow in OUT parameter name matching with limited 0/1-byte writes | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL regexp heap overflow enables arbitrary code execution via invalid encoding input affects pre-18.5/17.11/16.15/15.19/14.24 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | pg_dump/pg_dumpall/pg_restore restore-time RCE via psql \restrict/\unrestrict; affects pre-18.5/17.11/16.15/15.19/14.24 | secure-packages-rolling | Aug 24, 2026 | Sep 8, 2026 | |
| Open | High | PostgreSQL 'internal' type confusion enables arbitrary OS code execution by any user | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL pltcl/plperl 32-bit integer wraparound causes OOB write, potential RCE; pre-18.5 affected | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL regexp heap overflow enables OS-level RCE via invalid-encoding text; pre-18.5/17.11/16.15/15.19/14.24 affected | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL stack buffer overflow in argument name matching via OUT parameter count | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL plperl tied-hash return heap overflow enables OS code execution; affects pre 18.5/17.11/16.15/15.19/14.24 | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL portal/cursor type confusion permits arbitrary code execution as database OS user pre-18.5/17.11/16.15/15.19/14.24 | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | Type confusion in PostgreSQL ctid selectivity estimator enables memory disclosure via crafted non-ctid input | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | pg_restore_attribute_stats type confusion lets object creators execute OS code in PostgreSQL 18 before 18.5 | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | Logical decoding lacks authorization, REPLICATION users can dlopen arbitrary files, execute code as server account | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL pg_dump heap buffer overflow via crafted long transform lists enables OS user RCE | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL refint type confusion allows arbitrary code execution as DB OS user (pre-18.5/17.11/16.15/15.19/14.24) | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL pg_dump/pg_dumpall/pg_restore restore-time RCE via psql \restrict/\unrestrict expansion; CVE-2025-8714 bypass | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | Security: psql COPY FROM STDIN may execute data rows as commands on failure | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL EXTRACT() deparse SQL injection lets object owners escalate to superuser via deparse consumers | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL tsvector/tsquery integer wraparound enables unprivileged OOB write and potential RCE | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL fuzzystrmatch integer wraparound enables RCE via levenshtein/levenshtein_less_equal extreme inputs | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL to_char(timestamptz) heap overflow via long POSIX timezone allows OS-user RCE | secure-packages-26.05 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL tsvector/tsquery integer wraparound causes OOB write RCE; affects <18.5/17.11/16.15/15.19/14.24 | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL portal/cursor type confusion enables arbitrary OS-level code execution; before 18.5/17.11/16.15/15.19/14.24. | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | psql COPY FROM STDIN may execute data rows as commands on early failure | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL EXTRACT() deparse SQL injection lets object owners run superuser SQL; affects pg_dump and psql | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL regexp heap overflow permits RCE via invalid encoding; pre-18.5/17.11/16.15/15.19/14.24 affected | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | Heap buffer overflow in PostgreSQL plperl tied hash return enables function owner OS code execution | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | Restore-time code execution via psql \restrict/\unrestrict in PostgreSQL pg_dump/pg_dumpall/pg_restore | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL fuzzystrmatch integer wraparound enables RCE via levenshtein; affects versions before 18.5/17.11/16.15/15.19/14.24 | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | Heap overflow in PostgreSQL to_char(timestamptz) enables code execution via long timezone abbreviation | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | pg_dump heap overflow on long transform lists enables RCE; PostgreSQL <18.5/17.11/16.15/15.19/14.24 | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | Type confusion in PostgreSQL 'internal' arguments enables arbitrary code execution by any user via functions | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | mac80211 use-after-free: fast-RX reads RX status after mesh forwarding reuses skb->cb | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL ctid selectivity estimator type confusion leaks 4-byte memory data (pre-18.5/17.11/16.15/15.19/14.24) | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL 32-bit pltcl/plperl integer wraparound enables OOB write and RCE (pre-18.5/17.11/16.15/15.19/14.24) | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL 18.0-18.4 pg_restore_attribute_stats type confusion enables OS-level code execution via range/multirange | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 | |
| Open | High | PostgreSQL logical decoding auth flaw lets REPLICATION users dlopen arbitrary files, execute code | secure-packages-25.11 | Aug 25, 2026 | Sep 9, 2026 |