Skip to content
THREATWIRE

CVE

HighPoC Available

CVE-2026-15742

PostgreSQL fuzzystrmatch integer wraparound

A database user can reach an integer wraparound in fuzzystrmatch levenshtein functions and run code as the operating-system user of the server. Fixed on 13 August 2026. A public repository path exists. Not in CISA KEV.

CVSS
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Class
RCE
Status
PoC Available
KEV
Not in CISA KEV
0-day
No
Vendor
PostgreSQL
Products
PostgreSQL, fuzzystrmatch
Affected
PostgreSQL 18 before 18.6, 17 before 17.11, 16 before 16.15, 15 before 15.19, and 14 before 14.24, when fuzzystrmatch is installed.
Fixed
18.6, 17.11, 16.15, 15.19, and 14.24, published 13 August 2026.
Published
13 Aug 2026
Updated
5 Oct 2026

The status above is the claim. Links do not upgrade it.

CVE-2026-15742 is an integer wraparound in the PostgreSQL fuzzystrmatch contrib module. The project advisory, published with fixes on 13 August 2026, says extreme inputs to levenshtein() or levenshtein_less_equal() can direct writes across a large address range and execute code as the operating-system user running the database. The score is 8.8. The vector requires a low-privileged database account. It is not an unauthenticated network bug.

Fixed releases are 18.6, 17.11, 16.15, 15.19, and 14.24. The PostgreSQL project credits Ben Morris of Claude and Anthropic Research. CISA has not listed the CVE. A public path for this CVE exists under the kmkz/Exploits repository, so the status is PoC Available. The fix date is before that path was used as a public reference here, and the advisory does not describe exploitation before the fix, so this is not marked a 0-day. The inputs are not reprinted.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-15742