{"id":"CVE-2025-4207","year":2025,"sequence":4207,"component":"core server","score":5.9,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","first_published":"2025-05-08","source_url":"https://www.postgresql.org/support/security/CVE-2025-4207/","facts":{"affected":{"13":"13","14":"14","15":"15","16":"16","17":"17"},"affected_ranges":[{"from":"0","until":"13.21"},{"from":"14","until":"14.18"},{"from":"15","until":"15.13"},{"from":"16","until":"16.9"},{"from":"17","until":"17.5"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2025-4207","component":"core server","cvss_version":"3.0","description_en":"Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.","first_published":"2025-05-08","fixed":{"13":"13.21","14":"14.18","15":"15.13","16":"16.9","17":"17.5"},"id":"CVE-2025-4207","introduced":{},"published":{"13":"2025-05-08","14":"2025-05-08","15":"2025-05-08","16":"2025-05-08","17":"2025-05-08"},"score":5.9,"title":"PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation","url":"https://www.postgresql.org/support/security/CVE-2025-4207/","vector":"AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation","description":"Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"97810826580225939a520f0965cd2462d22aa0852e34ef5f670c9e338c2ca547"},"locales":["en","zh-Hans"],"fixes":[{"major":"13","fixed_version":"13.21","introduced":null,"published_date":"2025-05-08","facts":{"fixed":"13.21","introduced":null,"published":"2025-05-08"}},{"major":"14","fixed_version":"14.18","introduced":null,"published_date":"2025-05-08","facts":{"fixed":"14.18","introduced":null,"published":"2025-05-08"}},{"major":"15","fixed_version":"15.13","introduced":null,"published_date":"2025-05-08","facts":{"fixed":"15.13","introduced":null,"published":"2025-05-08"}},{"major":"16","fixed_version":"16.9","introduced":null,"published_date":"2025-05-08","facts":{"fixed":"16.9","introduced":null,"published":"2025-05-08"}},{"major":"17","fixed_version":"17.5","introduced":null,"published_date":"2025-05-08","facts":{"fixed":"17.5","introduced":null,"published":"2025-05-08"}}],"legacy":[{"source":"center","source_id":11,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":11,"cve":"2025-4207","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","details":null,"component":"core server","cvenumber":202504207,"description":"PostgreSQL GB18030 编码校验在处理校验失败的文本时，可能越过分配边界多读取 1 个字节","detailslink":"https://access.redhat.com/security/cve/CVE-2025-4207","legacyscore":"","newspost_id":null},"fixes":[{"source_id":44,"source_version_id":30,"major":"17","fixed_minor":5,"raw":{"id":44,"patch_id":11,"version_id":30,"fixed_minor":5},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":45,"source_version_id":29,"major":"16","fixed_minor":9,"raw":{"id":45,"patch_id":11,"version_id":29,"fixed_minor":9},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":46,"source_version_id":28,"major":"15","fixed_minor":13,"raw":{"id":46,"patch_id":11,"version_id":28,"fixed_minor":13},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":47,"source_version_id":27,"major":"14","fixed_minor":18,"raw":{"id":47,"patch_id":11,"version_id":27,"fixed_minor":18},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}},{"source_id":164,"source_version_id":26,"major":"13","fixed_minor":21,"raw":{"id":164,"patch_id":11,"version_id":26,"fixed_minor":21},"version_raw":{"id":26,"tree":13.0,"current":false,"docsgit":"","eoldate":"2025-11-13","reldate":"2025-11-13","testing":0,"supported":false,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":23,"firstreldate":"2020-09-24"}}]},{"source":"pgweb","source_id":11,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":11,"cve":"2025-4207","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","details":null,"component":"core server","cvenumber":202504207,"description":"PostgreSQL GB18030 编码校验在处理校验失败的文本时，可能越过分配边界多读取 1 个字节","detailslink":"https://access.redhat.com/security/cve/CVE-2025-4207","legacyscore":"","newspost_id":null},"fixes":[{"source_id":44,"source_version_id":30,"major":"17","fixed_minor":5,"raw":{"id":44,"patch_id":11,"version_id":30,"fixed_minor":5},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":45,"source_version_id":29,"major":"16","fixed_minor":9,"raw":{"id":45,"patch_id":11,"version_id":29,"fixed_minor":9},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":46,"source_version_id":28,"major":"15","fixed_minor":13,"raw":{"id":46,"patch_id":11,"version_id":28,"fixed_minor":13},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":47,"source_version_id":27,"major":"14","fixed_minor":18,"raw":{"id":47,"patch_id":11,"version_id":27,"fixed_minor":18},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}},{"source_id":164,"source_version_id":26,"major":"13","fixed_minor":21,"raw":{"id":164,"patch_id":11,"version_id":26,"fixed_minor":21},"version_raw":{"id":26,"tree":13.0,"current":false,"docsgit":"","eoldate":"2025-11-13","reldate":"2025-11-13","testing":0,"supported":false,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":23,"firstreldate":"2020-09-24"}}]}]}
