What is CVE-2026-73514?
The PostGIS address standardizer extension (through version 3.7.0) contains an out-of-bounds write vulnerability in the `standardize_address()` function, allowing database users who can supply controlled relation names to trigger memory corruption. This affects users leveraging the extension for address standardization. Immediate update to the version with commit 423570b is required.
Azərbaycanca: PostGIS ünvan standartlaşdırma genişlənməsi (3.7.0 və əvvəlki versiyalar) `standardize_address()` funksiyası vasitəsilə idarə olunan cədvəl adları təqdim edən istifadəçilər tərəfindən yaddaş korrupsiyasına səbəb ola biləcək out-of-bounds write zəifliyinə malikdir. Bu, həmin funksiyanı istifadə edən verilənlər bazası istifadəçilərinə təsir edir. Dərhal commit 423570b ilə düzəliş edilmiş versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-787
FAQ1
Which component of PostGIS does CVE-2026-73514 affect, and through which function is it exploited?
CVE-2026-73514 affects the PostGIS address standardizer extension and can be exploited through the `standardize_address()` function, leading to memory corruption.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.