CVE-2026-100387 – pgPointcloud through 1.2.5 heap out-of-bounds read via WKB deserialization

​CVE ID :CVE-2026-100387

Published : Sept. 25, 2026, 8:13 p.m. | 1 hour, 16 minutes ago

Description :pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with attacker-controlled size fields to copy heap memory into stored patches for exfiltration or crash the PostgreSQL backend.

Severity: 8.1 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More