{"id":"CVE-2026-100387","published":"2026-09-25T21:17:22.163","lastModified":"2026-09-25T21:17:22.163","description":"pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.","cvssScore":8.1,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","cwes":["CWE-125"],"vendors":[],"products":[],"references":[{"url":"https://github.com/pgpointcloud/pointcloud","tags":[]},{"url":"https://github.com/pgpointcloud/pointcloud/blob/v1.2.5/lib/pc_bytes.c#L1347-L1373","tags":[]},{"url":"https://github.com/pgpointcloud/pointcloud/issues/387","tags":[]},{"url":"https://github.com/pgpointcloud/pointcloud/pull/388","tags":[]},{"url":"https://www.vulncheck.com/advisories/pgpointcloud-through-1.2.5-heap-out-of-bounds-read-via-wkb-deserialization","tags":[]}],"exploitRefs":[{"url":"https://github.com/pgpointcloud/pointcloud","tags":[]},{"url":"https://github.com/pgpointcloud/pointcloud/blob/v1.2.5/lib/pc_bytes.c#L1347-L1373","tags":[]},{"url":"https://github.com/pgpointcloud/pointcloud/issues/387","tags":[]},{"url":"https://github.com/pgpointcloud/pointcloud/pull/388","tags":[]}],"hasPoc":true,"ai":null}