THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-16241 (LOW 3.8) — Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or

[NVD] CVE-2026-16241 (LOW 3.8) — Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or

mednvdPublished 2026-08-13

CVE-2026-16241 CVSS: 3.8 LOW Published: 2026-08-13T13:17:46.670

Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but r

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16241