Technology · PostgreSQL
PostgreSQL vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 14 vulnerabilities in PostgreSQL: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-6638, was published on 14 May 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About PostgreSQL
PostgreSQL is an open-source object-relational database system known for reliability, feature robustness, and performance.
Latest PostgreSQL vulnerabilities
- CVE-2026-6638: PostgreSQL SQL injection in REFRESH PUBLICATIONlowCVSS 3.7EPSS 0.0%
- CVE-2026-6637: PostgreSQL refint stack buffer overflow and SQL injectionhighCVSS 8.8EPSS 0.0%
- CVE-2026-6575: PostgreSQL buffer over-read in pg_restore_attribute_statsmediumCVSS 4.3EPSS 0.0%
- CVE-2026-6479: PostgreSQL uncontrolled recursion in SSL and GSS negotiationhighCVSS 7.5EPSS 0.0%
- CVE-2026-6478: PostgreSQL timing channel in MD5 password authenticationmediumCVSS 6.5EPSS 0.0%
- CVE-2026-6476: PostgreSQL SQL injection in pg_createsubscriberhighCVSS 7.2EPSS 0.0%
- CVE-2026-6475: PostgreSQL symlink following in pg_basebackup and pg_rewindhighCVSS 8.8EPSS 0.1%
- CVE-2026-6474: PostgreSQL format string vulnerability in timeofday functionmediumCVSS 4.3EPSS 0.0%
- CVE-2026-6473: PostgreSQL integer wraparound in multiple server featureshighCVSS 8.8EPSS 0.1%
- CVE-2026-6472: PostgreSQL missing authorization in CREATE TYPEmediumCVSS 5.4EPSS 0.0%
- CVE-2026-2007: PostgreSQL pg_trgm heap buffer overflowhighCVSS 8.2EPSS 0.3%
- CVE-2026-2006: PostgreSQL buffer overflow in multibyte character manipulationhighCVSS 8.8EPSS 0.7%
- CVE-2026-2005: PostgreSQL pgcrypto heap buffer overflow in contrib modulehighCVSS 8.8EPSS 0.7%
- CVE-2026-2004: PostgreSQL intarray remote code execution in selectivity estimatorhighCVSS 8.8EPSS 0.5%
Most severe PostgreSQL vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-2005: PostgreSQL pgcrypto heap buffer overflow in contrib modulehighCVSS 8.8EPSS 0.7%
- CVE-2026-2006: PostgreSQL buffer overflow in multibyte character manipulationhighCVSS 8.8EPSS 0.7%
- CVE-2026-2004: PostgreSQL intarray remote code execution in selectivity estimatorhighCVSS 8.8EPSS 0.5%
- CVE-2026-6473: PostgreSQL integer wraparound in multiple server featureshighCVSS 8.8EPSS 0.1%
- CVE-2026-6475: PostgreSQL symlink following in pg_basebackup and pg_rewindhighCVSS 8.8EPSS 0.1%
- CVE-2026-6637: PostgreSQL refint stack buffer overflow and SQL injectionhighCVSS 8.8EPSS 0.0%
- CVE-2026-2007: PostgreSQL pg_trgm heap buffer overflowhighCVSS 8.2EPSS 0.3%
- CVE-2026-6479: PostgreSQL uncontrolled recursion in SSL and GSS negotiationhighCVSS 7.5EPSS 0.0%
- CVE-2026-6476: PostgreSQL SQL injection in pg_createsubscriberhighCVSS 7.2EPSS 0.0%
- CVE-2026-6478: PostgreSQL timing channel in MD5 password authenticationmediumCVSS 6.5EPSS 0.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/postgresql.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "PostgreSQL vulnerabilities", https://junglewise.ai/threats/technologies/postgresql, 26 September 2026.