CVE-2026-16241: Integer Underflow (Wrap or Wraparound) in PostgreSQL
CVE-2026-16241 is an integer underflow vulnerability in PostgreSQL's ECPG client. It allows a database server administrator to cause a temporary denial of service by sending a malformed bytea value missing the required prefix. This leads to the client overwriting a large memory region, typically resulting in a segmentation fault. In rare cases, it may cause client-specific integrity issues. The vulnerability affects multiple PostgreSQL versions prior to 18.6, 17.11, 16.15, 15.19, and 14.24.
AI Analysis
Technical Summary
This vulnerability involves an integer underflow in the PostgreSQL ECPG client when processing a bytea value that lacks the mandatory prefix. An attacker with database server administrator privileges can exploit this flaw to cause the client to overwrite a large memory region with uncontrolled data. The usual outcome is a crash (SIGSEGV), but there is a potential for integrity impact on the client in rare cases. Affected versions include all releases before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24.
Potential Impact
The primary impact is a temporary denial of service against the ECPG client due to client crashes caused by memory corruption. There is no confidentiality impact, but there is a low integrity impact possibility in rare cases. The vulnerability requires high privileges (database server administrator) and does not involve user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch is confirmed, avoid exposing ECPG clients to untrusted database server administrators or malformed bytea inputs lacking the mandatory prefix.
CVE-2026-16241: Integer Underflow (Wrap or Wraparound) in PostgreSQL
Description
CVE-2026-16241 is an integer underflow vulnerability in PostgreSQL's ECPG client. It allows a database server administrator to cause a temporary denial of service by sending a malformed bytea value missing the required prefix. This leads to the client overwriting a large memory region, typically resulting in a segmentation fault. In rare cases, it may cause client-specific integrity issues. The vulnerability affects multiple PostgreSQL versions prior to 18.6, 17.11, 16.15, 15.19, and 14.24.
CVSS v3.1
Score 3.8low
Affected software
PostgreSQL
pkg:deb/postgresql/postgresqlRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves an integer underflow in the PostgreSQL ECPG client when processing a bytea value that lacks the mandatory prefix. An attacker with database server administrator privileges can exploit this flaw to cause the client to overwrite a large memory region with uncontrolled data. The usual outcome is a crash (SIGSEGV), but there is a potential for integrity impact on the client in rare cases. Affected versions include all releases before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24.
Potential Impact
The primary impact is a temporary denial of service against the ECPG client due to client crashes caused by memory corruption. There is no confidentiality impact, but there is a low integrity impact possibility in rare cases. The vulnerability requires high privileges (database server administrator) and does not involve user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch is confirmed, avoid exposing ECPG clients to untrusted database server administrators or malformed bytea inputs lacking the mandatory prefix.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- PostgreSQL
- Date Reserved
- 2026-07-20T01:55:34.563Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a7dc619bf8831d5393e53fd
Added to database: 08/13/2026, 13:26:49 UTC
Last enriched: 09/13/2026, 13:04:26 UTC
Last updated: 09/28/2026, 13:47:42 UTC
Views: 56
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.