
kmkz@kmkz_security
CVE-2026-15742 (PostgreSQL fuzzystrmatch OOB write) to RCE poc'd > time 2 sleep https://t.co/7EDFSw2yVp
22041162.3K
19.8K followersView on X
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE
If you run products in this scope, you should treat this CVE as relevant to your environment.

CVE-2026-15742 (PostgreSQL fuzzystrmatch OOB write) to RCE poc'd > time 2 sleep https://t.co/7EDFSw2yVp
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | postgresql | postgresql | - | - | - |