PT-2026-71463 · Postgresql Global Development Group+2 · Postgresql+2

CVE-2026-14663

·

Published

2026-08-12

·

Updated

2026-09-03

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 18.5 PostgreSQL versions prior to 17.11 PostgreSQL versions prior to 16.15 PostgreSQL versions prior to 15.19 PostgreSQL versions prior to 14.24
Description The pgcrypto module allows cleartext storage when disabled ciphers are used, enabling a user to recover cleartext through direct observation of the faulty ciphertext. The specific disabled ciphers are determined by the OpenSSL version and configuration. If an application accepts encrypted data as input, decryption may succeed even with an incorrect key, which bypasses the protection provided by the Modification Detection Code (MDC), a mechanism used to ensure data integrity. This issue affects the following functions: pgp sym encrypt(), pgp sym decrypt(), pgp pub encrypt(), pgp pub decrypt(), pgp sym encrypt bytea(), pgp sym decrypt bytea(), pgp pub encrypt bytea(), and pgp pub decrypt bytea().
Recommendations Update to version 18.5 or later. Update to version 17.11 or later. Update to version 16.15 or later. Update to version 15.19 or later. Update to version 14.24 or later. As a temporary mitigation, restrict the use of the affected pgp sym encrypt(), pgp sym decrypt(), pgp pub encrypt(), pgp pub decrypt(), pgp sym encrypt bytea(), pgp sym decrypt bytea(), pgp pub encrypt bytea(), and pgp pub decrypt bytea() functions.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-95723
BDU:2026-11952
BIT-POSTGRESQL-2026-14663
CVE-2026-14663
ECHO-F3CD-3A09-6569
OESA-2026-3420
OESA-2026-3421
OESA-2026-3422
OESA-2026-3423
OESA-2026-3424
OPENSUSE-SU-2026:11552-1
OPENSUSE-SU-2026:11553-1
OPENSUSE-SU-2026:11554-1
OPENSUSE-SU-2026:11555-1
OPENSUSE-SU-2026:11565-1
OPENSUSE-SU-2026:21699-1
OPENSUSE-SU-2026:21700-1
OPENSUSE-SU-2026:21701-1
OPENSUSE-SU-2026:21702-1
OPENSUSE-SU-2026:21703-1
RHSA-2026:57198
SUSE-SU-2026:3793-1
SUSE-SU-2026:3794-1
SUSE-SU-2026:3940-1
SUSE-SU-2026:3941-1
SUSE-SU-2026:3942-1
SUSE-SU-2026:3943-1
SUSE-SU-2026:3944-1
USN-8653-1

Affected Products

Linuxmint
Postgresql
Ubuntu