Vulnerability Bulletins |
CVE-2026-100387 |
|
| Affected software | POSTGRESQL |
| pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend. | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-100387 | |






