Skip to content
Critical Memory Disclosure Vulnerabilities in PostgreSQL PostGIS

Critical Memory Disclosure Vulnerabilities in PostgreSQL PostGIS

First seen 27 Sep 2026, 19:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 27, 2026 at 19:57 UTC
  • •CVE-2026-73515 affects PostgreSQL PostGIS versions 16, 17, and 18.
  • •CISA confirms active exploitation of these vulnerabilities in the wild.
  • •Immediate patching is recommended for affected systems to prevent memory disclosure and denial of service.

Multiple memory disclosure vulnerabilities have been identified in PostgreSQL PostGIS versions 16, 17, and 18, affecting Fedora 43 and 44. These vulnerabilities, tracked as CVE-2026-73515, allow for potential denial of service and memory disclosure via malformed FlatGeobuf buffers. CISA has confirmed active exploitation of these vulnerabilities in the wild, prompting urgent advisories for system administrators to apply patches. The vulnerabilities affect systems using PostgreSQL with PostGIS extensions, which are widely used in geographic information systems. The issues were first published on August 13, 2026, and have been backported in recent updates. Administrators are advised to upgrade their systems immediately to mitigate the risks associated with these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-13
CVE-2026-73515 published
Memory disclosure vulnerabilities in PostgreSQL PostGIS were disclosed, affecting multiple versions.
Linuxsecurity
2026-09-16
Backport fix released
Fedora released backport fixes for CVE-2026-73515 for affected PostgreSQL PostGIS versions.
Linuxsecurity
2026-09-27
Active exploitation confirmed
CISA confirmed that the vulnerabilities are being actively exploited in the wild, urging immediate action.
Linuxsecurity

More articles in this cluster (6)

Following this threat?

Track Fedora and CVE-2026-73515 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed