Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.postgresql.org/support/security/CVE-2026-18024/ |
|
History
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes after the end of a specific allocation, via a crafted text value. This is the same class of defect that CVE-2026-2006 fixed, though this instance has less impact. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | |
| Title | PostgreSQL ascii() function reads past end of buffer | |
| Weaknesses | CWE-126 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-08-13T15:39:03.530Z
Reserved: 2026-07-28T01:59:49.926Z
Link: CVE-2026-18024
Updated: 2026-08-13T15:38:55.256Z
Status : Received
Published: 2026-08-13T13:17:47.880
Modified: 2026-08-13T16:17:58.313
Link: CVE-2026-18024
No data.
OpenCVE Enrichment
Updated: 2026-08-13T15:15:13Z