Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
PostgreSQL: Critical Data Exposure through SQL Injection
RHSA-2026:4110
Summary
A security issue was found in PostgreSQL, a database management system. An attacker could potentially inject malicious SQL code to gain unauthorized access to sensitive data. Updating to the latest version is recommended to prevent this risk.
What to do
- Update redhat pg_repack to version 0:1.5.1-1.module+el9.6.0+22880+6b241eec.
- Update redhat pg_repack-debuginfo to version 0:1.5.1-1.module+el9.6.0+22880+6b241eec.
- Update redhat pg_repack-debugsource to version 0:1.5.1-1.module+el9.6.0+22880+6b241eec.
- Update redhat pgaudit to version 0:16.0-1.module+el9.4.0+20427+07482b8c.
- Update redhat pgaudit-debuginfo to version 0:16.0-1.module+el9.4.0+20427+07482b8c.
- Update redhat pgaudit-debugsource to version 0:16.0-1.module+el9.4.0+20427+07482b8c.
- Update redhat pgvector to version 0:0.6.2-2.module+el9.6.0+22979+c3d78d52.
- Update redhat pgvector-debuginfo to version 0:0.6.2-2.module+el9.6.0+22979+c3d78d52.
- Update redhat pgvector-debugsource to version 0:0.6.2-2.module+el9.6.0+22979+c3d78d52.
- Update redhat postgis to version 0:3.5.3-3.module+el9.7.0+23421+025f8139.
- Update redhat postgis-client to version 0:3.5.3-3.module+el9.7.0+23421+025f8139.
- Update redhat postgis-client-debuginfo to version 0:3.5.3-3.module+el9.7.0+23421+025f8139.
- Update redhat postgis-debuginfo to version 0:3.5.3-3.module+el9.7.0+23421+025f8139.
- Update redhat postgis-debugsource to version 0:3.5.3-3.module+el9.7.0+23421+025f8139.
- Update redhat postgis-docs to version 0:3.5.3-3.module+el9.7.0+23421+025f8139.
- Update redhat postgis-upgrade to version 0:3.5.3-3.module+el9.7.0+23421+025f8139.
- Update redhat postgis-upgrade-debuginfo to version 0:3.5.3-3.module+el9.7.0+23421+025f8139.
- Update redhat postgis-utils to version 0:3.5.3-3.module+el9.7.0+23421+025f8139.
- Update redhat postgres-decoderbufs to version 0:2.4.0-1.Final.module+el9.4.0+20427+07482b8c.
- Update redhat postgres-decoderbufs-debuginfo to version 0:2.4.0-1.Final.module+el9.4.0+20427+07482b8c.
- Update redhat postgres-decoderbufs-debugsource to version 0:2.4.0-1.Final.module+el9.4.0+20427+07482b8c.
- Update redhat postgresql to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-contrib to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-contrib-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-debugsource to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-docs to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-docs-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-plperl to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-plperl-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-plpython3 to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-plpython3-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-pltcl to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-pltcl-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-private-devel to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-private-libs to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-private-libs-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-server to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-server-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-server-devel to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-server-devel-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-static to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-test to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-test-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-test-rpm-macros to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-upgrade to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-upgrade-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-upgrade-devel to version 0:16.13-1.module+el9.7.0+24031+188c384c.
- Update redhat postgresql-upgrade-devel-debuginfo to version 0:16.13-1.module+el9.7.0+24031+188c384c.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| redhat | pg_repack | <= 0:1.5.1-1.module+el9.6.0+22880+6b241eec | 0:1.5.1-1.module+el9.6.0+22880+6b241eec |
| redhat | pg_repack-debuginfo | <= 0:1.5.1-1.module+el9.6.0+22880+6b241eec | 0:1.5.1-1.module+el9.6.0+22880+6b241eec |
| redhat | pg_repack-debugsource | <= 0:1.5.1-1.module+el9.6.0+22880+6b241eec | 0:1.5.1-1.module+el9.6.0+22880+6b241eec |
| redhat | pgaudit | <= 0:16.0-1.module+el9.4.0+20427+07482b8c | 0:16.0-1.module+el9.4.0+20427+07482b8c |
| redhat | pgaudit-debuginfo | <= 0:16.0-1.module+el9.4.0+20427+07482b8c | 0:16.0-1.module+el9.4.0+20427+07482b8c |
| redhat | pgaudit-debugsource | <= 0:16.0-1.module+el9.4.0+20427+07482b8c | 0:16.0-1.module+el9.4.0+20427+07482b8c |
| redhat | pgvector | <= 0:0.6.2-2.module+el9.6.0+22979+c3d78d52 | 0:0.6.2-2.module+el9.6.0+22979+c3d78d52 |
| redhat | pgvector-debuginfo | <= 0:0.6.2-2.module+el9.6.0+22979+c3d78d52 | 0:0.6.2-2.module+el9.6.0+22979+c3d78d52 |
| redhat | pgvector-debugsource | <= 0:0.6.2-2.module+el9.6.0+22979+c3d78d52 | 0:0.6.2-2.module+el9.6.0+22979+c3d78d52 |
| redhat | postgis | <= 0:3.5.3-3.module+el9.7.0+23421+025f8139 | 0:3.5.3-3.module+el9.7.0+23421+025f8139 |
| redhat | postgis-client | <= 0:3.5.3-3.module+el9.7.0+23421+025f8139 | 0:3.5.3-3.module+el9.7.0+23421+025f8139 |
| redhat | postgis-client-debuginfo | <= 0:3.5.3-3.module+el9.7.0+23421+025f8139 | 0:3.5.3-3.module+el9.7.0+23421+025f8139 |
| redhat | postgis-debuginfo | <= 0:3.5.3-3.module+el9.7.0+23421+025f8139 | 0:3.5.3-3.module+el9.7.0+23421+025f8139 |
| redhat | postgis-debugsource | <= 0:3.5.3-3.module+el9.7.0+23421+025f8139 | 0:3.5.3-3.module+el9.7.0+23421+025f8139 |
| redhat | postgis-docs | <= 0:3.5.3-3.module+el9.7.0+23421+025f8139 | 0:3.5.3-3.module+el9.7.0+23421+025f8139 |
| redhat | postgis-upgrade | <= 0:3.5.3-3.module+el9.7.0+23421+025f8139 | 0:3.5.3-3.module+el9.7.0+23421+025f8139 |
| redhat | postgis-upgrade-debuginfo | <= 0:3.5.3-3.module+el9.7.0+23421+025f8139 | 0:3.5.3-3.module+el9.7.0+23421+025f8139 |
| redhat | postgis-utils | <= 0:3.5.3-3.module+el9.7.0+23421+025f8139 | 0:3.5.3-3.module+el9.7.0+23421+025f8139 |
| redhat | postgres-decoderbufs | <= 0:2.4.0-1.Final.module+el9.4.0+20427+07482b8c | 0:2.4.0-1.Final.module+el9.4.0+20427+07482b8c |
| redhat | postgres-decoderbufs-debuginfo | <= 0:2.4.0-1.Final.module+el9.4.0+20427+07482b8c | 0:2.4.0-1.Final.module+el9.4.0+20427+07482b8c |
| redhat | postgres-decoderbufs-debugsource | <= 0:2.4.0-1.Final.module+el9.4.0+20427+07482b8c | 0:2.4.0-1.Final.module+el9.4.0+20427+07482b8c |
| redhat | postgresql | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-contrib | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-contrib-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-debugsource | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-docs | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-docs-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-plperl | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-plperl-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-plpython3 | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-plpython3-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-pltcl | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-pltcl-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-private-devel | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-private-libs | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-private-libs-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-server | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-server-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-server-devel | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-server-devel-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-static | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-test | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-test-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-test-rpm-macros | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-upgrade | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-upgrade-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-upgrade-devel | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
| redhat | postgresql-upgrade-devel-debuginfo | <= 0:16.13-1.module+el9.7.0+24031+188c384c | 0:16.13-1.module+el9.7.0+24031+188c384c |
Original title
Red Hat Security Advisory: postgresql:16 security update
osv CVSS3.1
8.8
- https://access.redhat.com/errata/RHSA-2026:4110 Vendor Advisory
- https://access.redhat.com/security/updates/classification/#important Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439324 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439325 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439326 Third Party Advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_4110.j... Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-2003 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2439322 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-2003 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-2003 Vendor Advisory
- https://www.postgresql.org/support/security/CVE-2026-2003/ Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-2004 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-2004 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-2004 Vendor Advisory
- https://www.postgresql.org/support/security/CVE-2026-2004/ Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-2005 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-2005 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-2005 Vendor Advisory
- https://www.postgresql.org/support/security/CVE-2026-2005/ Third Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-2006 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-2006 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-2006 Vendor Advisory
- https://www.postgresql.org/support/security/CVE-2026-2006/ Third Party Advisory
Published: 10 Mar 2026 · Updated: 13 Mar 2026 · First seen: 10 Mar 2026