THREAT OPS › Threat News › [NVD] CVE-2026-16241 (LOW 3.8) — Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or
[NVD] CVE-2026-16241 (LOW 3.8) — Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or
CVE-2026-16241 CVSS: 3.8 LOW Published: 2026-08-13T13:17:46.670
Integer underflow in PostgreSQL ECPG allows a database server administrator to achieve temporary denial of service against the ECPG client via sending a bytea value lacking the mandatory prefix. The client overwrites a huge memory region with bytes outside attacker knowledge or control. This typically yields a simple SIGSEGV, but r
Indicators of compromise
- CVE-2026-16241cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-16241