CVE-2026-73515Disclosure

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-13); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-13: 1Mentions · 2026-09-20: 1Mentions · 2026-09-21: 1Technical Details · 2026-08-13: 108-1309-2009-21
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-73515 Out-of-Bounds Read in PostGIS Before 3.7.0beta2 Leads to Memory Disclosure or Crash https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-73515

    Post summary

    A newly disclosed Out-of-Bounds Read vulnerability (CVE-2026-73515) in PostGIS prior to version 3.7.0beta2 could lead to memory disclosure or crash; no PoC, exploit, patch, or active exploitation is reported.

    00010101
    4.1K followersView on X
  • Nishanth@Nishanth_KJ

    If using PostGIS, ensure you update to version 3.5.3-6. This mitigates the critical security vulnerability CVE-2026-73515 in PostgreSQL deployments. #Security #PostgreSQL #PostGIS #CVE

    0000044
    66 followersView on X
  • Nishanth@Nishanth_KJ

    Check your PostGIS version. Oracle advisory updated `postgis` to `3.5.3-6` fixing CVE-2026-73515. Review this if you use Postgres on Linux 9 systems. #PostgreSQL #Linux #PostGIS #CVE

    0000039
    66 followersView on X

Explore more