logo

PoC Released for 20-Year Old PostgreSQL RCE Flaw

ID: b388d091-86f0-5e7e-9111-74024eb8bd74

STIX ID: report--b388d091-86f0-5e7e-9111-74024eb8bd74

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-19

Date Updated: 2026-05-22

Author: Lucas Martin

...
...

**Executive summary:** A public proof-of-concept exploit was released for CVE-2026-2005, a heap-based buffer overflow in PostgreSQL's pgcrypto extension that allows remote code execution and escalation to superuser by abusing a session-key parsing overflow; the upstream patch was issued in February 2026 and mitigations and patched versions are listed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.