Authenticated code execution via unchecked rule Type
Published Aug 13, 2026 · Updated Aug 13, 2026
Out-of-bounds write in PostGIS address_standardizer through 3.7.0 allows remote authenticated users to corrupt PostgreSQL backend memory. rules_add_rule passes a caller-controlled Type from a custom rules relation to classify_link, which indexes the fixed output-link table without checking the 0–4 class range. A database user able to select a custom rules relation can crash the backend or combine the write with address disclosure to gain PostgreSQL superuser privileges and execute code.
Summary
What happened
Out-of-bounds write in PostGIS address_standardizer through 3.7.0 allows remote authenticated users to corrupt PostgreSQL backend memory. rules_add_rule passes a caller-controlled Type from a custom rules relation to classify_link, which indexes the fixed output-link table without checking the 0–4 class range. A database user able to select a custom rules relation can crash the backend or combine the write with address disclosure to gain PostgreSQL superuser privileges and execute code.
The record
- CVE
- CVE-2026-73514
- Published
- Aug 13, 2026
- Updated
- Aug 13, 2026
- Vendor
- PostGIS
- Product
- address_standardizer
- Classifications
- CWE-787, T1190
- Attack vector
- network
- Privileges
- authenticated
Timeline
How it unfolded
- Aug 13, 2026CVE publishedPublication date reported by the CVE source.
- Aug 13, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=0 <423570b0dbf6cd9f6fc36de28a636e7b6e9aa8aa
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Public exploit references
- Oversized rule Type SQL proof of conceptproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Reported exploitation
- Managed PostgreSQL proof-of-concept exploitationreported exploitation
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo