What is CVE-2026-19385?
CVE-2026-19385 is a heap buffer overflow vulnerability in PostgreSQL's pg_dump utility when handling long function transform lists. It allows an object creator to execute arbitrary code as the operating system user running pg_dump via a crafted transform list. Users should upgrade to PostgreSQL versions 18.5, 17.11, 16.15, 15.19, 14.24 or later.
Azərbaycanca: CVE-2026-19385, PostgreSQL-in pg_dump alətində transform siyahılarının işlənməsi zamanı yaranan heap buffer overflow zəifliyidir. Bu, hücumçuya hazırlanmış transform siyahısı vasitəsilə pg_dump-u işlədən ƏS istifadəçisi hüquqlarında ixtiyari kod icrasına imkan verir. PostgreSQL-in təsirlənən versiyalarını 18.5, 17.11, 16.15, 15.19, 14.24 və ya daha yuxarı versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ1
Which PostgreSQL versions should be upgraded to mitigate CVE-2026-19385?
It is recommended to upgrade PostgreSQL to versions 18.5, 17.11, 16.15, 15.19, 14.24 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.