{"id":"CVE-2026-2004","year":2026,"sequence":2004,"component":"contrib module","score":8.8,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","first_published":"2026-02-12","source_url":"https://www.postgresql.org/support/security/CVE-2026-2004/","facts":{"affected":{"14":"14","15":"15","16":"16","17":"17","18":"18"},"affected_ranges":[{"from":"0","until":"14.21"},{"from":"15","until":"15.16"},{"from":"16","until":"16.12"},{"from":"17","until":"17.8"},{"from":"18","until":"18.2"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-2004","component":"contrib module","cvss_version":"3.0","description_en":"Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.","first_published":"2026-02-12","fixed":{"14":"14.21","15":"15.16","16":"16.12","17":"17.8","18":"18.2"},"id":"CVE-2026-2004","introduced":{},"published":{"14":"2026-02-12","15":"2026-02-12","16":"2026-02-12","17":"2026-02-12","18":"2026-02-12"},"score":8.8,"title":"PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code","url":"https://www.postgresql.org/support/security/CVE-2026-2004/","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"PostgreSQL intarray missing validation of type of input to selectivity estimator executes arbitrary code","description":"Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"0357c8f3251b77943464db67600eeaadbbe4e8e07028cbe253a63aada50098c5"},"locales":["en","zh-Hans"],"fixes":[{"major":"14","fixed_version":"14.21","introduced":null,"published_date":"2026-02-12","facts":{"fixed":"14.21","introduced":null,"published":"2026-02-12"}},{"major":"15","fixed_version":"15.16","introduced":null,"published_date":"2026-02-12","facts":{"fixed":"15.16","introduced":null,"published":"2026-02-12"}},{"major":"16","fixed_version":"16.12","introduced":null,"published_date":"2026-02-12","facts":{"fixed":"16.12","introduced":null,"published":"2026-02-12"}},{"major":"17","fixed_version":"17.8","introduced":null,"published_date":"2026-02-12","facts":{"fixed":"17.8","introduced":null,"published":"2026-02-12"}},{"major":"18","fixed_version":"18.2","introduced":null,"published_date":"2026-02-12","facts":{"fixed":"18.2","introduced":null,"published":"2026-02-12"}}],"legacy":[{"source":"center","source_id":4,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":4,"cve":"2026-2004","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":null,"component":"contrib module","cvenumber":202602004,"description":"PostgreSQL intarray 未校验传给选择性估算器的输入类型，可执行任意代码","detailslink":"https://access.redhat.com/security/cve/CVE-2026-2004","legacyscore":"","newspost_id":null},"fixes":[{"source_id":12,"source_version_id":31,"major":"18","fixed_minor":2,"raw":{"id":12,"patch_id":4,"version_id":31,"fixed_minor":2},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":13,"source_version_id":30,"major":"17","fixed_minor":8,"raw":{"id":13,"patch_id":4,"version_id":30,"fixed_minor":8},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":14,"source_version_id":29,"major":"16","fixed_minor":12,"raw":{"id":14,"patch_id":4,"version_id":29,"fixed_minor":12},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":15,"source_version_id":28,"major":"15","fixed_minor":16,"raw":{"id":15,"patch_id":4,"version_id":28,"fixed_minor":16},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":16,"source_version_id":27,"major":"14","fixed_minor":21,"raw":{"id":16,"patch_id":4,"version_id":27,"fixed_minor":21},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":4,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":4,"cve":"2026-2004","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":null,"component":"contrib module","cvenumber":202602004,"description":"PostgreSQL intarray 未校验传给选择性估算器的输入类型，可执行任意代码","detailslink":"https://access.redhat.com/security/cve/CVE-2026-2004","legacyscore":"","newspost_id":null},"fixes":[{"source_id":12,"source_version_id":31,"major":"18","fixed_minor":2,"raw":{"id":12,"patch_id":4,"version_id":31,"fixed_minor":2},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":13,"source_version_id":30,"major":"17","fixed_minor":8,"raw":{"id":13,"patch_id":4,"version_id":30,"fixed_minor":8},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":14,"source_version_id":29,"major":"16","fixed_minor":12,"raw":{"id":14,"patch_id":4,"version_id":29,"fixed_minor":12},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":15,"source_version_id":28,"major":"15","fixed_minor":16,"raw":{"id":15,"patch_id":4,"version_id":28,"fixed_minor":16},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":16,"source_version_id":27,"major":"14","fixed_minor":21,"raw":{"id":16,"patch_id":4,"version_id":27,"fixed_minor":21},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
