{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pgpointcloud--1.2.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pgpointcloud_project:pgpointcloud:*:*:*:*:*:postgresql:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-100387"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["pgPointcloud (\u003c= 1.2.5)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["PostgreSQL"],"content_html":"\u003cp\u003epgPointcloud through version 1.2.5 is susceptible to a heap out-of-bounds read vulnerability occurring during the deserialization of dimensional patch Well-Known Binary (WKB) data. This flaw stems from improper handling of size fields within the input data, which can be manipulated by an authenticated database user. By providing a crafted pcpatch value, an attacker can trick the PostgreSQL backend into reading and returning memory addresses outside of the allocated buffer. This can result in the leakage of sensitive data stored in the database heap or the termination of the backend process, leading to a denial-of-service condition. This vulnerability is significant for organizations utilizing the pgPointcloud extension for spatial data processing, as it permits unauthorized access to database memory from within the database environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated user to perform unauthorized information disclosure by reading adjacent memory segments, potentially exposing credentials, cryptographic keys, or sensitive records. Furthermore, the ability to induce an out-of-bounds read often leads to memory corruption, enabling attackers to crash the PostgreSQL backend service, which disrupts database availability for all users.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions include:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the pgPointcloud extension to the latest secure version addressing this vulnerability once available.\u003c/li\u003e\n\u003cli\u003eReview database access controls and minimize privileges for users with the ability to execute spatial functions or interact with pgPointcloud objects.\u003c/li\u003e\n\u003cli\u003eMonitor PostgreSQL logs for frequent backend crashes or service restarts that may indicate attempted exploitation of this memory corruption vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-25T22:55:24Z","date_published":"2026-09-25T22:55:24Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pgpointcloud-oob/","summary":"pgPointcloud versions through 1.2.5 contain a heap out-of-bounds read vulnerability in WKB deserialization that allows authenticated database users to exfiltrate heap memory or trigger backend service crashes.","title":"Heap Out-of-Bounds Read in pgPointcloud","url":"https://feed.craftedsignal.io/briefs/2026-09-pgpointcloud-oob/"}],"language":"en","title":"CraftedSignal Threat Feed - PgPointcloud (\u003c= 1.2.5)","version":"https://jsonfeed.org/version/1.1"}