Daily digest
Thursday 12 February 2026
A quiet day: only 9 new CVEs against a recent average of about 18. Severity skewed high: 5 high, 56% of the total. One arrived with exploitation evidence or public exploit code already attached. postgresql was the most-affected vendor with 4.
New this day, ranked by depth score
The 9 that matter most of the 9 published.
CVE-2026-2005High· 8.8PoCHeap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database
Heap buffer overflow in PostgreSQL pgcrypto allows a ciphertext provider to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 17.8, 16.12, 15.16, and 14.21 are affected.
CVE-2026-2006High· 8.8Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun
Missing validation of multibyte character length in PostgreSQL text manipulation allows a database user to issue crafted queries that achieve a buffer overrun. That suffices to execute arbitrary code as the operating system user running…
CVE-2026-2004High· 8.8Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database
Missing validation of type of input in PostgreSQL intarray extension selectivity estimator function allows an object creator to execute arbitrary code as the operating system user running the database. Versions before PostgreSQL 18.2, 1…
CVE-2026-2007High· 8.2Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string
Heap buffer overflow in PostgreSQL pg_trgm allows a database user to achieve unknown impacts via a crafted input string. The attacker has limited control over the byte patterns to be written, but we have not ruled out the viability of a…
CVE-2026-25949High· 7.5Traefik is an HTTP reverse proxy and load balancer
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sendi…
CVE-2026-21438Medium· 5.3webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map
webtransport-go: Memory Exhaustion Attack due to Missing Cleanup of Streams Map
CVE-2026-63762MediumSurrealDB vulnerable to Denial of Service through scripting function memory edge case
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
CVE-2025-69752Medium· 4.3An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.
An issue in the "My Details" user profile functionality of Ideagen Q-Pulse 7.1.0.32 allows an authenticated user to view other users' profile information by modifying the objectKey HTTP parameter in the My Details page URL.
CVE-2025-67860Low· 3.8NeuVector scanner insecurely handles passwords as command arguments
NeuVector scanner insecurely handles passwords as command arguments
Most-affected vendors
By CVEs published in the period.