PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 13 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Postgis
Postgis postgis |
|
| Vendors & Products |
Postgis
Postgis postgis |
Thu, 13 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails to verify that the subsequent string body is contained within the supplied buffer before materializing it into a SQL-visible value, enabling memory disclosure or denial of service. | |
| Title | PostGIS < 3.7.0beta2 Out-of-Bounds Read via FlatGeobuf Buffer | |
| Weaknesses | CWE-125 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-13T17:11:44.844Z
Reserved: 2026-08-12T19:29:19.865Z
Link: CVE-2026-73515
No data.
Status : Received
Published: 2026-08-13T16:19:05.333
Modified: 2026-08-13T18:18:18.230
Link: CVE-2026-73515
No data.
OpenCVE Enrichment
Updated: 2026-08-13T19:15:03Z
Weaknesses