{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/postgis/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-73515"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PostGIS"],"_cs_severities":["high"],"_cs_tags":["vulnerability","postgis","memory-corruption"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003ePostGIS, a widely used spatial database extender for PostgreSQL, contains an out-of-bounds read vulnerability (CVE-2026-73515) in its FlatGeobuf property metadata decoder. The flaw exists because the decoder verifies the presence of a string length field within the provided FlatGeobuf buffer but fails to validate that the associated string body is fully contained within the buffer boundaries before materializing the value into a SQL-visible object.\u003c/p\u003e\n\u003cp\u003eThis vulnerability can be exploited by an authenticated attacker to perform unauthorized memory disclosure or trigger a server crash, resulting in a denial of service condition. The issue affects all versions of PostGIS prior to 3.7.0beta2. Given that PostGIS is commonly deployed in cloud-managed database environments (such as Neon or Supabase) and exposed via SQL interfaces, this flaw poses a significant risk to data confidentiality and service availability for applications that process untrusted geospatial data.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains access to a database instance where the PostGIS extension is enabled and accessible via SQL.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malformed FlatGeobuf buffer containing an inconsistent string length field.\u003c/li\u003e\n\u003cli\u003eAttacker executes a SQL query that invokes a PostGIS function (e.g., ST_GeomFromFlatGeobuf) and passes the malicious buffer as an argument.\u003c/li\u003e\n\u003cli\u003eThe PostGIS FlatGeobuf decoder parses the metadata and identifies the string length field.\u003c/li\u003e\n\u003cli\u003eThe decoder fails to validate the buffer boundary, resulting in an out-of-bounds memory read when attempting to process the string body.\u003c/li\u003e\n\u003cli\u003eThe database engine returns sensitive memory contents as a result of the SQL query (memory disclosure) or triggers an unhandled segmentation fault (crash).\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved: exfiltrating private process memory or rendering the database service unresponsive.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows authenticated attackers to disclose sensitive information stored in memory or cause a denial of service by crashing the PostgreSQL backend process. This poses a particular risk to multi-tenant or managed database environments where users may be able to influence the data passed to PostGIS functions. The vulnerability has been assigned a CVSS 3.1 score of 8.1 (High).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to mitigate the risk associated with CVE-2026-73515:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the PostGIS extension to version 3.7.0beta2 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit database access logs to identify users or service accounts that frequently invoke PostGIS functions, specifically those handling FlatGeobuf input.\u003c/li\u003e\n\u003cli\u003eReview and restrict database permissions to ensure that only trusted users have the ability to execute spatial functions involving external data types.\u003c/li\u003e\n\u003cli\u003eMonitor database error logs for repeated segmentation faults or process crashes, which may indicate attempted exploitation of this memory corruption vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T16:57:01Z","date_published":"2026-08-13T16:57:01Z","id":"https://feed.craftedsignal.io/briefs/2026-08-postgis-oob-read/","summary":"PostGIS versions prior to 3.7.0beta2 are vulnerable to an out-of-bounds read in the FlatGeobuf property metadata decoder, allowing authenticated attackers to trigger a denial of service or perform memory disclosure via malformed input.","title":"Out-of-Bounds Read Vulnerability in PostGIS FlatGeobuf Decoder","url":"https://feed.craftedsignal.io/briefs/2026-08-postgis-oob-read/"}],"language":"en","title":"CraftedSignal Threat Feed - PostGIS","version":"https://jsonfeed.org/version/1.1"}