CVE-2026-19385: PostgreSQL pg_dump heap buffer overflow executes arbitrary code
Heap buffer overflow in PostgreSQL pgdump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pgdump, via a crafted transform list. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PostgreSQL pg_dumpto a version that resolves this vulnerability.Fixed in 18.5 - Upgrade
Upgrade
PostgreSQL pg_dumpto a version that resolves this vulnerability.Fixed in 17.11 - Upgrade
Upgrade
PostgreSQL pg_dumpto a version that resolves this vulnerability.Fixed in 16.15 - Upgrade
Upgrade
PostgreSQL pg_dumpto a version that resolves this vulnerability.Fixed in 15.19 - Upgrade
Upgrade
PostgreSQL pg_dumpto a version that resolves this vulnerability.Fixed in 14.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19385?
The severity of CVE-2026-19385 is high, with a score of 8.8.
How do I fix CVE-2026-19385?
To fix CVE-2026-19385, you should upgrade to PostgreSQL versions 18.5, 17.11, 16.15, 15.19, or 14.24 or later.
What type of vulnerability is CVE-2026-19385?
CVE-2026-19385 is a heap buffer overflow vulnerability.
What impact does CVE-2026-19385 have on PostgreSQL pg_dump?
CVE-2026-19385 allows an object creator to execute arbitrary code as the operating system user running pg_dump.
Which versions of PostgreSQL are affected by CVE-2026-19385?
PostgreSQL versions prior to 18.5, 17.11, 16.15, 15.19, and 14.24 are affected by CVE-2026-19385.