vulns.co
/
GKData.io MCP

MEMemory safety and parser contracts · 2 min read

PostgreSQL extension estimator trusted an unchecked input type

Wiz confirms a USD 30,000 competition award for Daniel Firer’s PostgreSQL entry, uniquely mapped by the organizer to CVE-2026-2004.

Read the primary source MEMemory safety and parser contractsReviewed 2026-10-02

Root cause

The extension’s selectivity estimator accepted input without checking that its type matched the routine’s expectations. This broke the contract between database objects an authorized user could create and native extension code running with database-process authority.

Demonstrated impact

The vendor confirms possible code execution as the database operating-system account. A user needed permission to install the vulnerable extension, or an existing installation plus object-creation permission. The public sources do not establish a universal unauthenticated or cross-tenant compromise.

Lessons for review

  • Validate input types at extension boundaries before applying native-code assumptions.
  • Review extension installation and object-creation privileges together; either permission in isolation can hide the relevant trust boundary.
  • Verify the vendor’s fixed releases and keep the database process identity limited to necessary resources.

Award and evidence

USD 30,000Competition Award · Organizer Confirmed

One individually identified competition entry. The organizer uses $; its current rules establish US-dollar notation but concern 2026, not an archived 2025 rules snapshot. Exact award decision and cash settlement are unknown.

Matched the organizer’s named PostgreSQL award to the tracker’s exact CVE, then checked the vendor advisory and CNA prerequisites. Summary remains within the published technical evidence.

  • The technical basis is the vendor advisory, not a detailed researcher walkthrough; discovery reasoning beyond that evidence is unknown.
  • The December competition demonstration, February advisory publication, award announcement and unknown payment date are distinct events.
  • Current rules provide explicit USD context but are not the archived 2025 rules.

Recorded timeline

Published
2026-02-12explicit · Publication of the vendor CNA record; no separate detailed researcher article was established.
Public Disclosure
2025-12-10explicit · Public competition demonstration; separate from later vendor advisory and technical publication.
Fixed
2026-02-12explicit · Vendor release date for PostgreSQL 18.2, 17.8, 16.12, 15.16 and 14.21; individual deployment dates remain unknown.
Award Announced
2025-12-16explicit · Organizer recap confirms the per-entry award; decision and payment dates remain unknown.

Sources and provenance

  1. ZeroDay.cloud 2025 individual competition results Nir Ohfeld / Wiz Research · reviewed 2026-10-02
  2. ZeroDay.cloud vulnerability tracker Wiz / ZeroDay.cloud · reviewed 2026-10-02
  3. ZeroDay.cloud current rules: US-dollar denomination Wiz · reviewed 2026-10-02
  4. PostgreSQL CVE-2026-2004 security advisory PostgreSQL · reviewed 2026-10-02
  5. CVE-2026-2004 PostgreSQL CNA record PostgreSQL CNA / CVE Program · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software