CVE-2026-15742
PostgreSQL fuzzystrmatch integer wraparound
A database user can reach an integer wraparound in fuzzystrmatch levenshtein functions and run code as the operating-system user of the server. Fixed on 13 August 2026. A public repository path exists. Not in CISA KEV.
- CVSS
- 8.8
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Class
- RCE
- Status
- PoC Available
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- PostgreSQL
- Products
- PostgreSQL, fuzzystrmatch
- Affected
- PostgreSQL 18 before 18.6, 17 before 17.11, 16 before 16.15, 15 before 15.19, and 14 before 14.24, when fuzzystrmatch is installed.
- Fixed
- 18.6, 17.11, 16.15, 15.19, and 14.24, published 13 August 2026.
- CWE
- CWE-190
- Published
- 13 Aug 2026
- Updated
- 5 Oct 2026
The status above is the claim. Links do not upgrade it.
CVE-2026-15742 is an integer wraparound in the PostgreSQL fuzzystrmatch contrib module. The project advisory, published with fixes on 13 August 2026, says extreme inputs to levenshtein() or levenshtein_less_equal() can direct writes across a large address range and execute code as the operating-system user running the database. The score is 8.8. The vector requires a low-privileged database account. It is not an unauthenticated network bug.
Fixed releases are 18.6, 17.11, 16.15, 15.19, and 14.24. The PostgreSQL project credits Ben Morris of Claude and Anthropic Research. CISA has not listed the CVE. A public path for this CVE exists under the kmkz/Exploits repository, so the status is PoC Available. The fix date is before that path was used as a public reference here, and the advisory does not describe exploitation before the fix, so this is not marked a 0-day. The inputs are not reprinted.