CVE-2026-2005PoC(postgresql / postgresql)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch postgresql postgresql systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-120

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postgresql

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 36 mentions across 24 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 16 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 30 signals
  • Disclosure: 11 classified signals
  • Peaked 23d ago at 4 mentions (2026-02-12); latest day: 2
  • 36 total mentions across 24 days

Affected systems

Vendors
Products
postgresql

Deep dive

Activity timeline36 mentions / 24d
01234Mentions · 2026-02-12: 4Mentions · 2026-02-13: 2Mentions · 2026-02-14: 1Mentions · 2026-02-17: 1Mentions · 2026-02-18: 1Mentions · 2026-02-19: 1Mentions · 2026-02-25: 1Mentions · 2026-03-06: 1Mentions · 2026-03-10: 1Mentions · 2026-03-12: 1Mentions · 2026-03-31: 1Mentions · 2026-05-05: 2Mentions · 2026-05-07: 4Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Mentions · 2026-05-18: 2Mentions · 2026-05-19: 3Mentions · 2026-05-20: 1Mentions · 2026-05-26: 1Mentions · 2026-06-09: 1Mentions · 2026-06-10: 1Mentions · 2026-06-12: 1Mentions · 2026-06-15: 1Mentions · 2026-07-23: 2PoC Mentioned / Linked · 2026-05-05: 2PoC Mentioned / Linked · 2026-05-07: 4PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-05-19: 3PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-05-26: 1PoC Mentioned / Linked · 2026-06-10: 1PoC Mentioned / Linked · 2026-06-15: 1PoC Mentioned / Linked · 2026-07-23: 2Exploit Tool / Code · 2026-05-05: 1Exploit Tool / Code · 2026-05-13: 1Exploit Tool / Code · 2026-05-19: 2Exploit Tool / Code · 2026-05-26: 1Exploit Tool / Code · 2026-06-15: 1Exploit Tool / Code · 2026-07-23: 2Patch / Workaround · 2026-02-12: 2Patch / Workaround · 2026-02-13: 2Patch / Workaround · 2026-02-14: 1Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-25: 1Patch / Workaround · 2026-03-06: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-05-19: 2Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-07-23: 1Technical Details · 2026-02-12: 4Technical Details · 2026-02-13: 1Technical Details · 2026-02-14: 1Technical Details · 2026-02-25: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-31: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-07: 4Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 3Technical Details · 2026-05-20: 1Technical Details · 2026-05-26: 1Technical Details · 2026-06-09: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-15: 1Technical Details · 2026-07-23: 202-1202-1402-1802-2503-1003-3105-0705-1305-1905-2606-1006-1507-23
Signal classification5 categories
PoC
1336.1%
Disclosure
1130.6%
Patch
822.2%
General
38.3%
Exploit
12.8%
Referenced assets27 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-124
Disclosure3Patch1
2026-02-132
Patch2
2026-02-141
Patch1
2026-02-171
Disclosure1
2026-02-181
Patch1
2026-02-191
Patch1
2026-02-251
Disclosure1
2026-03-061
Patch1
2026-03-101
Disclosure1
2026-03-121
Patch1
2026-03-311
Disclosure1
2026-05-052
Exploit1PoC1
2026-05-074
Disclosure1PoC3
2026-05-121
Disclosure1
2026-05-131
PoC1
2026-05-182
Disclosure1General1
2026-05-193
PoC3
2026-05-201
PoC1
2026-05-261
PoC1
2026-06-091
General1
2026-06-101
Disclosure1
2026-06-121
General1
2026-06-151
PoC1
2026-07-232
PoC2
Full discourse20 posts
  • Varik@D4RK7ET
    PoC

    PoC for CVE-2026-2005 - PostgreSQL pgcrypto Heap Overflow Exploit https://github.com/var77/CVE-2026-2005 #CVE20262005 #PostgreSQL #pgcrypto #Exploit #PoC #pwn https://t.co/EUJbHacTSU

    Post summary

    A Proof of Concept exploit for CVE‑2026‑2005, a heap overflow in PostgreSQL’s pgcrypto, has been published on GitHub, with no indication of active exploitation or a patch.

    1330137729.7K
    339 followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    RCE PoC - CVE-2026-2005 — PostgreSQL pgcrypto heap overflow RCE exploit https://github.com/dinosn/cve-2026-2005

    Post summary

    This tweet announces a Proof of Concept for CVE‑2026‑2005, a heap overflow in PostgreSQL pgcrypto that enables remote code execution, and includes a link to the exploit code.

    03511355510.0K
    160.9K followersView on X
  • Swissky@pentest_swissky
    Disclosure

    CVE-2026-2005: PostgreSQL pgcrypto heap buffer overflow leading to RCE - @wiz_io https://www.zeroday.cloud/blog/postgres-xint

    Post summary

    The tweet announces CVE‑2026‑2005, a heap buffer overflow in PostgreSQL pgcrypto that can cause remote code execution, and links to a blog post likely containing further details.

    117053265.0K
    21.9K followersView on X
  • Tim Becker@tjbecker
    Disclosure

    > Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Note that pgcrypto (and other extensions) can be enabled by any user! This does not require admin. https://www.postgresql.org/support/security/CVE-2026-2005/

    Post summary

    The text announces a heap buffer overflow in PostgreSQL pgcrypto that permits arbitrary code execution, notes the extension can be enabled by any user, and links to a vendor advisory that presumably contains a patch.

    16038154.2K
    2.1K followersView on X
  • Nicolas Krassas@Dinosn
    Exploit

    CVE-2026-2005 — PostgreSQL pgcrypto heap overflow RCE exploit (lab) https://github.com/dinosn/cve-2026-2005

    Post summary

    A lab‑based exploit for CVE‑2026‑2005 against PostgreSQL pgcrypto is linked, indicating functional exploit code, but no evidence of live exploitation or vendors’ fixes.

    030159786
    155.5K followersView on X
  • Moritz Sanft@stdoutput
    General

    @carste1n Glad that you're interested in the talk. This should work: https://docs.google.com/presentation/d/11wokD_IAO5QFwA0tZzEKfqCI-Ne1iJ3XASnE7SW5zxs/edit?usp=sharing Let me know if it doesn't. Talk recording should also be available soon-ish. For now, you can also take the blog post as a more detailed reference along the slides: https://www.zeroday.cloud/blog/postgresql-cve-2026-2005-deep-dive

    Post summary

    The message refers to a talk and a blog post about CVE‑2026‑2005 but does not contain direct PoC, exploitation evidence, patch information, or technical details.

    120147905
    1.3K followersView on X
  • dbugs@ptdbugs
    PoC

    PostgreSQL pgcrypto heap buffer overflow executes arbitrary code CVE: CVE-2026-2005 PT ID: PT-2026-7845 Vendor: PostgreSQL Product: PostgreSQL CVSS: 8.8 Credits: Team Xint Code Description: Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-2005 • https://www.postgresql.org/support/security/CVE-2026-2005/ PoC/Exploit: https://github.com/var77/CVE-2026-2005 #dbugs_vuln

    Post summary

    The post discloses a PostgreSQL pgcrypto heap buffer overflow (CVE-2026-2005) that enables arbitrary code execution and provides a PoC/exploit via GitHub, but it does not report active exploitation or patch information.

    020113622
    3.0K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos PostgreSQL ❗ CVE-2026-2004 ❗ CVE-2026-2005 ❗ CVE-2026-2006 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-postgresql/ https://t.co/GCOXi3X40y

    Post summary

    Three PostgreSQL CVEs (CVE-2026-2004, CVE-2026-2005, CVE-2026-2006) are disclosed; additional information is available via the provided link.

    02073764
    6.6K followersView on X
  • Gray Hats@the_yellow_fall
    PoC

    Technical details and GitHub PoC exploits disclosed for PostgreSQL pgcrypto CVE-2026-2005. Low-privilege users can seize root superuser RCE. Patch now! #PostgreSQL #pgcrypto #CyberSecurity #InfoSec #RCE #VulnerabilityAlert #CVE20262005 #PoCExploit https://securityonline.info/postgresql-pgcrypto-vulnerability-cve-2026-2005-poc-exploit-disclosed/ https://t.co/1FNUUNtEjr

    Post summary

    The post announces a GitHub PoC for CVE‑2026‑2005 that enables RCE from low‑privilege to root, and indicates a patch has been released.

    02063603
    12.5K followersView on X
  • iototsecnews@iototsecnews
    PoC

    PostgreSQL pgcrypto の RCE 脆弱性 CVE-2026-2005:PoC が登場 https://iototsecnews.jp/2026/05/19/20-year-old-postgresql-flaw-gets-public-poc-exploit-for-remote-code-execution/ PostgreSQL の暗号化エクステンション pgcrypto に見つかった、深刻な脆弱性を解説する記事です。問題の原因は、20 年前からのレガシーコード内に存在する、PGP セッションキー解析時のメモリ管理不備 (ヒープバッファ・オーバーフロー) にあります。この CVE-2026-2005 を悪用する 攻撃者は、メモリ構造を破壊して内部の権限設定を書き換え、データベースのスーパーユーザーを奪取することが可能になります。さらに、正規のデータベース機能を悪用し、サーバ上で任意の OS コマンドをリモート実行する恐れもあります。 すでに PoC コードが公開されているため、 管理者はパッチの適用やアクセス制限などの対策が不可欠です。 #CVE20262005 #PoC #PostgreSQL #Vulnerability

    Post summary

    本記事は PostgreSQL の pgcrypto 拡張に対する RCE 脆弱性 (CVE-2026-2005) を説明し、ヒープバッファ・オーバーフローによりスーパー ユーザー権限取得と任意 OS コマンド実行が可能であると指摘。 PoC コードが公開されているため、管理者はパッチ適用とアクセス制限を実施すべきと警告している。

    01011114
    490 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    PostgreSQL の脆弱性 CVE-2026-2005/2006 が FIX:Wiz の http://ZeroDay.Cloud イベント https://iototsecnews.jp/2026/05/04/wiz-zeroday-cloud-event-reveals-20-year-old-postgresql-vulnerabilities/ 世界中で広く利用されているデータベース PostgreSQL に、20 年近くも前から潜んでいた深刻な脆弱性が発見されました。問題の原因は、データベース内で暗号化や復号を行うためのエクステンション pgcrypto に存在する、データの長さを正しく確認しない不備にあります。具体的には、悪意を持って細工されたメッセージや文字データを処理しようとすると、あらかじめ用意されたメモリの範囲を超えてデータが書き込まれてしまうオーバーフローが発生します (CVE-2026-2005/CVE-2026-2006)。これにより、データベース権限の乗っ取りや、サーバ上での任意のコマンド実行に至る恐れがあります。また、 MariaDB でも、メモリ管理の不具合の脆弱性 (CVE-2026-32710) が見つかっています。ご利用のチームは、ご注意ください。 #CVE20262005 #CVE20262006 #CVE202632710 #PostgreSQL #Vulnerability #ZeroDayCloud

    Post summary

    The post announces the discovery of long‑hidden PostgreSQL vulnerabilities (CVE‑2026‑2005/2006) that cause buffer overflows and could lead to arbitrary command execution, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    02010138
    491 followersView on X
  • Grok@grok
    Disclosure

    The latest Postgres CVEs (fixed in the Feb 12 2026 release: 18.2, 17.8, 16.12, 15.16, 14.21) are: - CVE-2026-2003: oidvector memory disclosure (medium) - CVE-2026-2004: intarray selectivity estimator exec code (high) - CVE-2026-2005: pgcrypto heap buffer overflow exec code (high) - CVE-2026-2006: multibyte char length buffer overrun exec code (high) - CVE-2026-2007: pg_trgm heap buffer overflow (high, 18.x only) AWS RDS/Aurora has no public patches or timeline yet.

    Post summary

    The post announces five new Postgres CVEs (CVE‑2026‑2003 to CVE‑2026‑2007) with technical details and notes they are fixed in the Feb 12 2026 release; AWS RDS/Aurora currently has no public patches or timeline.

    1000285
    8.2M followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-42897 2 - CVE-2026-2005 3 - CVE-2020-25728 4 - CVE-2026-8936 5 - CVE-2026-3910 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five CVEs as trending but provides no technical details, PoC, exploit, patch, or evidence of active exploitation.

    00011127
    1.7K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    『This release fixes 5 security vulnerabilities and over 65 bugs reported over the last several months.』 CVE-2026-2003 CVE-2026-2004 CVE-2026-2005 CVE-2026-2006 CVE-2026-2007 PostgreSQL: PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 Released! https://www.postgresql.org/about/news/postgresql-182-178-1612-1516-and-1421-released-3235/

    Post summary

    PostgreSQL has released new versions (18.2, 17.8, 16.12, 15.16, 14.21) that address five security CVEs and over 65 additional bugs.

    00020372
    6.7K followersView on X
  • キタきつね@foxbook
    PoC

    概念実証(PoC)エクスプロイトが公開されました:20年前のPostgreSQL pgcryptoの脆弱性(CVE-2026-2005)により、完全なスーパーユーザー権限 PoC Exploit Publicly Disclosed: 20-Year-Old PostgreSQL pgcrypto Flaw (CVE-2026-2005) Grants Full Superuser RCE #DailyCyberSecurity (May 19) https://securityonline.info/postgresql-pgcrypto-vulnerability-cve-2026-2005-poc-exploit-disclosed/

    Post summary

    A proof‑of‑concept exploit for CVE‑2026‑2005 has been publicly disclosed, demonstrating full superuser RCE via PostgreSQL's pgcrypto module.

    00010307
    4.8K followersView on X
  • moton@moton
    PoC

    PoC Exploit Publicly Disclosed: 20-Year-Old PostgreSQL pgcrypto Flaw (CVE-2026-2005) Grants Full Superuser RCE - https://securityonline.info/postgresql-pgcrypto-vulnerability-cve-2026-2005-poc-exploit-disclosed/

    Post summary

    The post announces a publicly disclosed Proof of Concept exploit for CVE‑2026‑2005, detailing a full superuser remote code execution flaw in PostgreSQL’s pgcrypto, but does not provide exploit code, tooling, or indications of active exploitation.

    0001080
    659 followersView on X
  • Blackstorm Security@blackstormsecbr
    Disclosure

    CVE-2026-2006: Encoding bug in PostgreSQL pgcrypto leads to Remote Code Execution: (article) https://www.zeroday.cloud/blog/postgresql-cve-2026-2005-deep-dive (slides) https://docs.google.com/presentation/d/11wokD_IAO5QFwA0tZzEKfqCI-Ne1iJ3XASnE7SW5zxs/edit?slide=id.p#slide=id.p #cve #vulnerability #zeroday #cybersecurity #informationsecurity #informationsecurity https://t.co/WhrbNP5QB1

    Post summary

    The post announces a new PostgreSQL pgcrypto encoding bug (CVE-2026-2006) that allows remote code execution, offers links to an article and slides, but does not provide PoC, exploit code, or active exploitation details.

    00001173
    2.0K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Full Tweet CVE-2026-2005 — PostgreSQL pgcrypto heap overflow RCE exploit (lab) 0day Intel: CVE-2026-2005 — PostgreSQL pgcrypto heap overflow RCE exploit (lab) https://t.co

    Post summary

    The tweet announces a new, lab‑tested PostgreSQL pgcrypto heap overflow that leads to remote code execution, providing basic vulnerability details and a placeholder link.

    1000068
    155 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    0day Intel: CVE-2026-2005 — PostgreSQL pgcrypto heap overflow RCE exploit (lab)

    Post summary

    A laboratory proof‑of‑concept exploit demonstrates a heap overflow in PostgreSQL's pgcrypto module that could allow remote code execution; no real‑world attacks or patch information are reported.

    1000064
    155 followersView on X
  • Lyrie.ai@lyrie_ai
    PoC

    CVE-2026-2005: CVE-2026-2005 — PostgreSQL pgcrypto heap overflow RCE exploit (lab) 0day Intel: CVE-2026-2005 — PostgreSQL pgcrypto heap overflow RCE exploit (lab) https://t.co

    Post summary

    The tweet signals that a laboratory proof‑of‑concept exploit exists against PostgreSQL’s pgcrypto heap overflow, but no public exploit code or evidence of live attacks is provided.

    1000070
    155 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppostgresqlpostgresql---

Explore more