ALPINE-CVE-2026-2007
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 12 Feb 2026, 14:16
Last modified:14 Mar 2026, 04:41
Vulnerability Summary
Overall Risk (default)
medium
33/100 CVSS Score
8.2 HIGH
3.1 (osv_alpine)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
12 Feb 2026, 14:16
Published
Vulnerability first disclosed
14 Mar 2026, 04:41
Last Modified
Vulnerability information updated
Description
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.
CVSS Metrics
- v3.1•HIGH•Score: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Affected Systems
- alpine•postgresql15
< 15.16-r0 | < 15.17-r0
- alpine•postgresql16
< 16.12-r0 | < 16.13-r0 | < 16.12-r0 | < 16.13-r0 | < 16.12-r0 | < 16.13-r0
- alpine•postgresql17
< 17.8-r0 | < 17.9-r0 | < 17.8-r0 | < 17.9-r0 | < 17.8-r0 | < 17.9-r0
- alpine•postgresql18
< 18.2-r0