THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-90775 (MEDIUM 6.5) — PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, c

[NVD] CVE-2026-90775 (MEDIUM 6.5) — PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, c

mednvdPublished 2026-09-13

CVE-2026-90775 CVSS: 6.5 MEDIUM Published: 2026-09-13T12:17:16.400

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and t

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90775