Missing authorization in PostgreSQL DDL commands allows an object creator to achieve denial of service against ALTER and DROP of the type, via creating a dependency on the type. Many DDL operations did check the privilege, but assigning a range subtype and referencing the type from an SQL expression did not. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade postgresql17Upgrade postgresql15Upgrade postgresql16Upgrade postgresql18 | Aug 17, 2026 | Aug 13, 2026 |
| Debian | — | Upgrade postgresql-17Upgrade postgresql-15 | Aug 16, 2026 | Aug 16, 2026 |
| Freebsd | — | Upgrade postgresql17-serverUpgrade postgresql14-serverUpgrade postgresql18-serverUpgrade postgresql15-serverUpgrade postgresql16-server | Aug 17, 2026 | Aug 16, 2026 |
| Postgres | — | Upgrade to PostgreSQL version 17.11Upgrade to PostgreSQL version 15.19Upgrade to PostgreSQL version 14.24Upgrade to PostgreSQL version 18.5Upgrade to PostgreSQL version 16.15 | Aug 14, 2026 | Aug 13, 2026 |
| Ubuntu | — | Upgrade postgresql-18Upgrade postgresql-14Upgrade postgresql-16 | Aug 20, 2026 | Aug 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub