CVE-2026-90775
PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an ar
CVSS
6.5
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Sep 13, 2026 · Last modified: Sep 13, 2026 · CWE-125
Not enough EPSS history yet.
PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.
- github.comhttps://github.com/postgis/address_standardizer
- github.comhttps://github.com/postgis/address_standardizer/blob/e987949e0fccff6a0e7a6d3f86814d5c7a01f481/NEWS.md
- github.comhttps://github.com/postgis/address_standardizer/blob/v3.7.0/src/analyze.c#L860
- github.comhttps://github.com/postgis/address_standardizer/blob/v3.7.0/src/gamma.c#L301-L311
- github.comhttps://github.com/postgis/address_standardizer/commit/a5cb4b1360a040973092f13b1af97a718e7e104a
- github.comhttps://github.com/postgis/address_standardizer/commit/e987949e0fccff6a0e7a6d3f86814d5c7a01f481
- github.comhttps://github.com/postgis/address_standardizer/pull/6
- www.vulncheck.comhttps://www.vulncheck.com/advisories/postgis-address-standardizer-through-3.7.0-out-of-bounds-read-via-unvalidated-rule-weight
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-906813.3 LOW—
———A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.3hCVE-2026-339682.8 LOW—
———An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.5hCVE-2026-339622.8 LOW—
———An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.6hCVE-2026-522972.9 LOW—
———FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.10hCVE-2026-522962.9 LOW—
———FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.10hCVE-2026-383322.9 LOW—
———TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.11h