{"id":"CVE-2026-2003","year":2026,"sequence":2003,"component":"core server","score":4.3,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","first_published":"2026-02-12","source_url":"https://www.postgresql.org/support/security/CVE-2026-2003/","facts":{"affected":{"14":"14","15":"15","16":"16","17":"17","18":"18"},"affected_ranges":[{"from":"0","until":"14.21"},{"from":"15","until":"15.16"},{"from":"16","until":"16.12"},{"from":"17","until":"17.8"},{"from":"18","until":"18.2"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-2003","component":"core server","cvss_version":"3.0","description_en":"Improper validation of type \"oidvector\" in PostgreSQL allows a database user to disclose a few bytes of server memory. We have not ruled out viability of attacks that arrange for presence of confidential information in disclosed bytes, but they seem unlikely. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.","first_published":"2026-02-12","fixed":{"14":"14.21","15":"15.16","16":"16.12","17":"17.8","18":"18.2"},"id":"CVE-2026-2003","introduced":{},"published":{"14":"2026-02-12","15":"2026-02-12","16":"2026-02-12","17":"2026-02-12","18":"2026-02-12"},"score":4.3,"title":"PostgreSQL oidvector discloses a few bytes of memory","url":"https://www.postgresql.org/support/security/CVE-2026-2003/","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL oidvector 会泄露少量内存字节","description":"PostgreSQL oidvector 会泄露少量内存字节","details":null,"format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2026-2003","cvenumber":202602003,"description":"PostgreSQL oidvector 会泄露少量内存字节","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2026-2003","id":5,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"source":"center","source_id":5,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2026-2003","cvenumber":202602003,"description":"PostgreSQL oidvector 会泄露少量内存字节","details":null,"detailslink":"https://access.redhat.com/security/cve/CVE-2026-2003","id":5,"legacyscore":"","newspost_id":null,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"},"source":"pgweb","source_id":5,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"73f9ac3807328c9a06c07238d9a032a7844ef60d78940598ea7136128af498da"},"locales":["en","zh-Hans"],"fixes":[{"major":"14","fixed_version":"14.21","introduced":null,"published_date":"2026-02-12","facts":{"fixed":"14.21","introduced":null,"published":"2026-02-12"}},{"major":"15","fixed_version":"15.16","introduced":null,"published_date":"2026-02-12","facts":{"fixed":"15.16","introduced":null,"published":"2026-02-12"}},{"major":"16","fixed_version":"16.12","introduced":null,"published_date":"2026-02-12","facts":{"fixed":"16.12","introduced":null,"published":"2026-02-12"}},{"major":"17","fixed_version":"17.8","introduced":null,"published_date":"2026-02-12","facts":{"fixed":"17.8","introduced":null,"published":"2026-02-12"}},{"major":"18","fixed_version":"18.2","introduced":null,"published_date":"2026-02-12","facts":{"fixed":"18.2","introduced":null,"published":"2026-02-12"}}],"legacy":[{"source":"center","source_id":5,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":5,"cve":"2026-2003","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","details":null,"component":"core server","cvenumber":202602003,"description":"PostgreSQL oidvector 会泄露少量内存字节","detailslink":"https://access.redhat.com/security/cve/CVE-2026-2003","legacyscore":"","newspost_id":null},"fixes":[{"source_id":17,"source_version_id":31,"major":"18","fixed_minor":2,"raw":{"id":17,"patch_id":5,"version_id":31,"fixed_minor":2},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":18,"source_version_id":30,"major":"17","fixed_minor":8,"raw":{"id":18,"patch_id":5,"version_id":30,"fixed_minor":8},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":19,"source_version_id":29,"major":"16","fixed_minor":12,"raw":{"id":19,"patch_id":5,"version_id":29,"fixed_minor":12},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":20,"source_version_id":28,"major":"15","fixed_minor":16,"raw":{"id":20,"patch_id":5,"version_id":28,"fixed_minor":16},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":21,"source_version_id":27,"major":"14","fixed_minor":21,"raw":{"id":21,"patch_id":5,"version_id":27,"fixed_minor":21},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":5,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":5,"cve":"2026-2003","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","details":null,"component":"core server","cvenumber":202602003,"description":"PostgreSQL oidvector 会泄露少量内存字节","detailslink":"https://access.redhat.com/security/cve/CVE-2026-2003","legacyscore":"","newspost_id":null},"fixes":[{"source_id":17,"source_version_id":31,"major":"18","fixed_minor":2,"raw":{"id":17,"patch_id":5,"version_id":31,"fixed_minor":2},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":18,"source_version_id":30,"major":"17","fixed_minor":8,"raw":{"id":18,"patch_id":5,"version_id":30,"fixed_minor":8},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":19,"source_version_id":29,"major":"16","fixed_minor":12,"raw":{"id":19,"patch_id":5,"version_id":29,"fixed_minor":12},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":20,"source_version_id":28,"major":"15","fixed_minor":16,"raw":{"id":20,"patch_id":5,"version_id":28,"fixed_minor":16},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":21,"source_version_id":27,"major":"14","fixed_minor":21,"raw":{"id":21,"patch_id":5,"version_id":27,"fixed_minor":21},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
