Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve
unknown impacts via a crafted input string. The attacker has limited control
over the byte patterns to be written, but we have not ruled out the viability of
attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
The PostgreSQL project thanks Heikki Linnakangas for reporting this problem.
| Affected Version | Fixed In | Fix Published |
|---|---|---|
| 18 | 18.2 | Feb. 12, 2026 |
For more information about PostgreSQL versioning, please visit the versioning page.
| Overall Score | 8.2 |
|---|---|
| Component | contrib module |
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
If you wish to report a new security vulnerability in PostgreSQL, please send an email to security@postgresql.org.
For reporting non-security bugs, please see the Report a Bug page.