Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Postgis
Postgis address Standardizer |
|
| Vendors & Products |
Postgis
Postgis address Standardizer |
Thu, 13 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by providing a rules table with a classification Type value exceeding the fixed class range. Attackers can craft a malicious rules table entry with an oversized rule type value that is used without bounds checking as an index into an internal output-link table, resulting in an out-of-bounds write. | |
| Title | PostGIS address_standardizer Out-of-Bounds Write via standardize_address() | |
| Weaknesses | CWE-787 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T12:46:52.825Z
Reserved: 2026-08-12T19:29:19.865Z
Link: CVE-2026-73514
Updated: 2026-08-13T17:24:05.439Z
Status : Received
Published: 2026-08-13T16:19:05.190
Modified: 2026-08-13T18:18:18.097
Link: CVE-2026-73514
No data.
OpenCVE Enrichment
Updated: 2026-08-14T09:31:09Z