VDB
GCVE-110-NCSC-2026-321
GCVE-110-NCSC-2026-321
Advisory PublishedCVSS 9.4/10
PostgreSQL versions prior to 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 have a vulnerability in the CREATE STATISTICS command due to missing schema CREATE privilege checks, enabling denial of service and potential information disclosure.
Weaknesses (CWE)
CWE-862Missing AuthorizationCWE-190Integer Overflow or WraparoundCWE-248Uncaught ExceptionCWE-1287Improper Validation of Specified Type of InputCWE-122Heap-based Buffer OverflowCWE-129Improper Validation of Array IndexCWE-134Use of Externally-Controlled Format StringCWE-61UNIX Symbolic Link (Symlink) FollowingCWE-242Use of Inherently Dangerous FunctionCWE-385Covert Timing ChannelCWE-121Stack-based Buffer OverflowCWE-522Insufficiently Protected CredentialsCWE-470Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')CWE-416Use After FreeCWE-125Out-of-bounds ReadCWE-120Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-312Cleartext Storage of Sensitive InformationCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-295Improper Certificate ValidationCWE-124Buffer Underwrite ('Buffer Underflow')CWE-758Reliance on Undefined, Unspecified, or Implementation-Defined BehaviorCWE-787Out-of-bounds WriteCWE-476NULL Pointer DereferenceCWE-367Time-of-check Time-of-use (TOCTOU) Race ConditionCWE-908Use of Uninitialized ResourceCWE-426Untrusted Search PathCWE-369Divide By ZeroCWE-128Wrap-around ErrorCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-191Integer Underflow (Wrap or Wraparound)CWE-73External Control of File Name or PathCWE-59Improper Link Resolution Before File Access ('Link Following')CWE-770Allocation of Resources Without Limits or ThrottlingCWE-822Untrusted Pointer DereferenceCWE-327Use of a Broken or Risky Cryptographic AlgorithmCWE-319Cleartext Transmission of Sensitive InformationCWE-611Improper Restriction of XML External Entity ReferenceCWE-674Uncontrolled RecursionCWE-696Incorrect Behavior OrderCWE-1333Inefficient Regular Expression ComplexityCWE-347Improper Verification of Cryptographic SignatureCWE-407Inefficient Algorithmic ComplexityCWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')CWE-23Relative Path TraversalCWE-1284Improper Validation of Specified Quantity in InputCWE-348Use of Less Trusted Source
Risk Scores
CVSS 3.1
9.4/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| IBM | vers:unknown/* | — | — |
Aliases
CVE-2025-12817CVE-2025-12818CVE-2025-15649CVE-2026-12087CVE-2026-14970CVE-2026-15061CVE-2026-15065CVE-2026-15068CVE-2026-15078CVE-2026-16243CVE-2026-16439CVE-2026-16441CVE-2026-16656CVE-2026-16686CVE-2026-16690CVE-2026-16703CVE-2026-16706CVE-2026-16814CVE-2026-16816CVE-2026-16817CVE-2026-16818CVE-2026-16819CVE-2026-16822CVE-2026-16824CVE-2026-16825CVE-2026-16827CVE-2026-16829CVE-2026-16831CVE-2026-16833CVE-2026-16834CVE-2026-16836CVE-2026-16837CVE-2026-16838CVE-2026-16839CVE-2026-16840CVE-2026-16841CVE-2026-16842CVE-2026-16844CVE-2026-16845CVE-2026-16846CVE-2026-16847CVE-2026-16848CVE-2026-16849CVE-2026-16850CVE-2026-16851CVE-2026-16852CVE-2026-16855CVE-2026-16857CVE-2026-16862CVE-2026-16864CVE-2026-16865CVE-2026-16866CVE-2026-16869CVE-2026-16872CVE-2026-16873CVE-2026-16874CVE-2026-16875CVE-2026-16877CVE-2026-16882CVE-2026-16883CVE-2026-16885CVE-2026-16886CVE-2026-16888CVE-2026-16890CVE-2026-16891CVE-2026-16894CVE-2026-16897CVE-2026-16901CVE-2026-16903CVE-2026-16909CVE-2026-16911CVE-2026-16913CVE-2026-16914CVE-2026-16917CVE-2026-16919CVE-2026-16922CVE-2026-16923CVE-2026-16924CVE-2026-16925CVE-2026-16926CVE-2026-16927CVE-2026-16928CVE-2026-16932CVE-2026-16934CVE-2026-16935CVE-2026-16936CVE-2026-16937CVE-2026-16943CVE-2026-16944CVE-2026-16945CVE-2026-16946CVE-2026-16951CVE-2026-16952CVE-2026-16958CVE-2026-16964CVE-2026-16972CVE-2026-16973CVE-2026-16980CVE-2026-16989CVE-2026-16991CVE-2026-16996CVE-2026-16997CVE-2026-17000CVE-2026-17003CVE-2026-17006CVE-2026-17007CVE-2026-17009CVE-2026-17024CVE-2026-17040CVE-2026-17060CVE-2026-17118CVE-2026-17120CVE-2026-17121CVE-2026-17122CVE-2026-17124CVE-2026-17136CVE-2026-17138CVE-2026-17141CVE-2026-17142CVE-2026-17145CVE-2026-17152CVE-2026-17157CVE-2026-17159CVE-2026-17160CVE-2026-17163CVE-2026-17165CVE-2026-17168CVE-2026-17170CVE-2026-17171CVE-2026-17195CVE-2026-17422CVE-2026-17423CVE-2026-17424CVE-2026-17425CVE-2026-17436CVE-2026-18670CVE-2026-18716CVE-2026-18822CVE-2026-18824CVE-2026-18828CVE-2026-18832CVE-2026-18835CVE-2026-18840CVE-2026-18842CVE-2026-19437CVE-2026-19442CVE-2026-19446CVE-2026-19448CVE-2026-19449CVE-2026-19653CVE-2026-19783CVE-2026-2003CVE-2026-2004CVE-2026-2005CVE-2026-2006CVE-2026-22007CVE-2026-22013CVE-2026-22016CVE-2026-22018CVE-2026-22021CVE-2026-34268CVE-2026-41254CVE-2026-46968CVE-2026-47010CVE-2026-47021CVE-2026-47027CVE-2026-47057CVE-2026-47058CVE-2026-47059CVE-2026-47063CVE-2026-48959CVE-2026-48962CVE-2026-59995CVE-2026-59996CVE-2026-59997CVE-2026-59999CVE-2026-60000CVE-2026-60001CVE-2026-60002CVE-2026-60147CVE-2026-6472CVE-2026-6473CVE-2026-6474CVE-2026-6475CVE-2026-6477CVE-2026-6478CVE-2026-6637CVE-2026-8368CVE-2026-8400CVE-2026-8829
References
Browse GCVE Records
69,226 records in the GCVE database · Updated August 24, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.