ALPINE-CVE-2026-2007

Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 12 Feb 2026, 14:16
Last modified:14 Mar 2026, 04:41

Vulnerability Summary

Overall Risk (default)
medium
33/100
CVSS Score
8.2 HIGH
3.1 (osv_alpine)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Feb 2026, 14:16
Published
Vulnerability first disclosed
14 Mar 2026, 04:41
Last Modified
Vulnerability information updated

Description

Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of attacks that lead to privilege escalation. PostgreSQL 18.1 and 18.0 are affected.

CVSS Metrics

  • v3.1HIGHScore: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Affected Systems

  • alpinepostgresql15

    < 15.16-r0 | < 15.17-r0

  • alpinepostgresql16

    < 16.12-r0 | < 16.13-r0 | < 16.12-r0 | < 16.13-r0 | < 16.12-r0 | < 16.13-r0

  • alpinepostgresql17

    < 17.8-r0 | < 17.9-r0 | < 17.8-r0 | < 17.9-r0 | < 17.8-r0 | < 17.9-r0

  • alpinepostgresql18

    < 18.2-r0

References (1)