CVE-2026-73514: PostGIS address_standardizer Out-of-Bounds Write via standardize_address()

Published Aug 13, 2026
·
Updated

The addressstandardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardizeaddress() to trigger memory corruption by providing a rules table with a classification Type value exceeding the fixed class range. Attackers can craft a malicious rules table entry with an oversized rule type value that is used without bounds checking as an index into an internal output-link table, resulting in an out-of-bounds write.

Affected Software

1 affected component
PostGIS address_standardizer<=3.7.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade PostGIS address_standardizer extension to a version that resolves this vulnerability.

    Fixed in 3.7.0Patch 423570b

Event History

Aug 13, 2026
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-73514?

CVE-2026-73514 has a severity rating of 8.8, indicating it is a high-risk vulnerability.

2

How do I fix CVE-2026-73514?

To fix CVE-2026-73514, upgrade to the latest version of PostGIS address_standardizer, which is patched in version 3.7.1 or later.

3

What type of vulnerability is CVE-2026-73514?

CVE-2026-73514 is an out-of-bounds write vulnerability impacting the address_standardizer extension for PostGIS.

4

Who is affected by CVE-2026-73514?

Any database user with the ability to supply caller-controlled relation names to the standardize_address() function is affected by CVE-2026-73514.

5

What can happen if CVE-2026-73514 is exploited?

Exploitation of CVE-2026-73514 can lead to memory corruption, potentially allowing an attacker to execute arbitrary code.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203