CVE-2026-2005: Public PoC Released for Critical 20-Year-Old PostgreSQL pgcrypto RCE Vulnerability
A public proof-of-concept exploit has been released for CVE-2026-2005, a critical remote code execution flaw in PostgreSQL’s pgcrypto extension rooted in nearly 20-year-old code. The exploit chains a heap buffer overflow through ASLR bypass to achieve PostgreSQL superuser privileges and OS command execution.
Itagora tiene in archivio titolo e sommario per la ricerca interna. Il testo completo resta sulla fonte. Il link in uscita non invia referrer.