vulns.co
/
GKData.io MCP

MEMemory safety and parser contracts · 2 min read

PostgreSQL text-encoding invariant failure caused memory corruption

A PostgreSQL encoding-validation failure earned Team Bugz Bunnies a $30,000 individual-entry award at ZeroDay.cloud. The vendor subsequently issued CVE-2026-2006.

Read the primary source MEMemory safety and parser contractsReviewed 2026-10-02

Root cause

A trusted extension did not uphold a database-wide text-encoding invariant, while downstream text routines relied on that invariant for memory-safe length calculations. Defensive reviews should verify contracts across parser and extension boundaries.

Demonstrated impact

Vendor confirms that an authenticated database user could reach code execution with the database operating-system account's privileges.

Lessons for review

  • Validate encoding contracts at every trusted extension boundary.
  • Avoid relying on unverified text invariants for memory-length calculations.
  • Apply supported vendor fixes and retain regression coverage.

Award and evidence

USD 30,000Competition Award · Organizer Confirmed

Per-finding competition award to a team, not a vendor bounty or the team's combined event earnings. Exact cash-transfer date is unknown. USD normalization of the organizer's dollar-denominated competition award.

Primary public sources read; reward distinguished from maximums and aggregates. Historical defensive summary only; no vulnerability testing performed.

  • This is a per-finding competition award, not a traditional vendor bounty; keep award_type visible
  • Do not count the team's $40,000 combined Grafana and PostgreSQL earnings as this finding's reward
  • Actual funds-transfer date not published

Recorded timeline

Reported
2025-12-11explicit
Fixed
2026-02-12explicit
Award Announced
2025-12-16explicit · Organizer recap announces the individual entry award; exact award/transfer date not published.
Published
2026-05-04inferred · On-stage demonstration and vendor disclosure are explicitly December 11, 2025. Organizer payout recap was published December 16; cash transfer date is not stated. Detailed researcher article is dated May 4, with year contextualized by its 2026 fix timeline.
Public Disclosure
2025-12-11explicit · Public competition demonstration; detailed technical publication followed in 2026.

Sources and provenance

  1. PostgreSQL text-encoding invariant failure caused memory corruption Wiz / ZeroDay.cloud · reviewed 2026-10-02
  2. Supporting primary disclosure source Wiz / ZeroDay.cloud · reviewed 2026-10-02
  3. Supporting primary disclosure source Paul Gerste, Moritz Sanft, Team Bugz Bunnies · reviewed 2026-10-02
  4. PostgreSQL CVE-2026-2006 vendor advisory PostgreSQL Global Development Group · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software