What is CVE-2026-18024?
CVE-2026-18024 is a buffer over-read vulnerability in PostgreSQL's ascii() SQL function, allowing a user to read up to 3 bytes beyond a specific memory allocation via a crafted text value. This flaw is similar to CVE-2026-2006 but with lower impact. Updating to PostgreSQL versions 18.5, 17.11, 16.8 or later is recommended.
Azərbaycanca: CVE-2026-18024 PostgreSQL-in ascii() SQL funksiyasında "buffer over-read" zəifliyidir. Xüsusi hazırlanmış mətn dəyəri vasitəsilə istifadəçi müəyyən yaddaş bölgəsindən sonrakı 3 bayta qədər məlumatı oxuya bilər. Bu, CVE-2026-2006 ilə eyni qüsur sinfinə aiddir, lakin təsiri daha azdır. PostgreSQL-i 18.5, 17.11, 16.8 və ya daha yeni versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
How many additional bytes of memory data can an attacker read using the CVE-2026-18024 PostgreSQL vulnerability?
An attacker can read up to 3 bytes of data beyond a specific memory allocation via a crafted text value.
Which PostgreSQL versions are recommended to patch the CVE-2026-18024 vulnerability?
Updating to PostgreSQL versions 18.5, 17.11, 16.8 or later is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.