Description
PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.
Published: 2026-09-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Crash)
Action: Immediate Patch
AI Analysis

Impact

This vulnerability in PostGIS address_standardizer before version 3.7.1 allows a malicious user to insert rule table entries with Weight values that exceed the expected bounds. The unchecked Weight is used as an array index, causing an out‑of‑bounds read in the load_value array during rule processing. The resulting memory access violation crashes the PostgreSQL backend process, bringing down the entire database cluster and terminating all active sessions. The weakness is a classic out‑of‑bounds read (CWE‑125).

Affected Systems

All installations of PostGIS address_standardizer version 3.7.0 and earlier are vulnerable. The flaw applies to the address_standardizer module used by PostgreSQL for normalizing street addresses. The vulnerability is not limited to any specific platform or configuration and affects any database instance that loads or executes arbitrary rule tables via address_standardizer.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed or widely known exploits yet. A threat actor would need to supply address_standardizer enabled and sufficient privileges to load the table. Failure to validate the Weight value permits the attacker to trigger a crash cluster.

Generated by OpenCVE AI on September 15, 2026 at 17:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade PostGIS address_standardizer to the latest released version that contains the weight‑validation patch (currently 3.7.1 or newer).
  • If an immediate upgrade is impossible, remove the address_standardizer module or prevent it from loading untrusted rule tables by restricting table creation to trusted users only and applying custom scripts to validate Weight fields before insertion.
  • Apply a database restart or spin‑up a new cluster backup to recover from any partial crash caused by a malicious rule table, and monitor PostgreSQL logs for out‑of‑bounds read warnings or unexpected backend restarts.

Generated by OpenCVE AI on September 15, 2026 at 17:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Postgis
Postgis address Standardizer
Vendors & Products Postgis
Postgis address Standardizer

Sun, 13 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.
Title PostGIS address_standardizer through 3.7.0 Out-of-Bounds Read via Unvalidated Rule Weight
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Postgis Address Standardizer
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:23:06.091Z

Reserved: 2026-09-13T10:54:46.826Z

Link: CVE-2026-90775

cve-icon Vulnrichment

Updated: 2026-09-18T17:17:06.160Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-13T12:17:16.400

Modified: 2026-09-24T21:08:22.573

Link: CVE-2026-90775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses