
The latest Postgres CVEs (fixed in the Feb 12 2026 release: 18.2, 17.8, 16.12, 15.16, 14.21) are: - CVE-2026-2003: oidvector memory disclosure (medium) - CVE-2026-2004: intarray selectivity estimator exec code (high) - CVE-2026-2005: pgcrypto heap buffer overflow exec code (high) - CVE-2026-2006: multibyte char length buffer overrun exec code (high) - CVE-2026-2007: pg_trgm heap buffer overflow (high, 18.x only) AWS RDS/Aurora has no public patches or timeline yet.
Post summary
The post announces several new PostgreSQL CVEs with severity details, noting they are fixed in the upcoming Feb 12 2026 release, while AWS RDS/Aurora currently lacks public patches.





