
CVE-2026-32286 The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field le… https://www.cve.org/CVERecord?id=CVE-2026-32286
Post summary
The text reports a vulnerability in PostgreSQL’s DataRow.Decode function where a malicious server can send a DataRow message with a negative field length, indicating improper input validation.
