Root cause
A trusted extension did not uphold a database-wide text-encoding invariant, while downstream text routines relied on that invariant for memory-safe length calculations. Defensive reviews should verify contracts across parser and extension boundaries.
Demonstrated impact
Vendor confirms that an authenticated database user could reach code execution with the database operating-system account's privileges.
Lessons for review
- Validate encoding contracts at every trusted extension boundary.
- Avoid relying on unverified text invariants for memory-length calculations.
- Apply supported vendor fixes and retain regression coverage.
Award and evidence
Per-finding competition award to a team, not a vendor bounty or the team's combined event earnings. Exact cash-transfer date is unknown. USD normalization of the organizer's dollar-denominated competition award.
Primary public sources read; reward distinguished from maximums and aggregates. Historical defensive summary only; no vulnerability testing performed.
- This is a per-finding competition award, not a traditional vendor bounty; keep award_type visible
- Do not count the team's $40,000 combined Grafana and PostgreSQL earnings as this finding's reward
- Actual funds-transfer date not published
Recorded timeline
- Reported
- 2025-12-11explicit
- Fixed
- 2026-02-12explicit
- Award Announced
- 2025-12-16explicit · Organizer recap announces the individual entry award; exact award/transfer date not published.
- Published
- 2026-05-04inferred · On-stage demonstration and vendor disclosure are explicitly December 11, 2025. Organizer payout recap was published December 16; cash transfer date is not stated. Detailed researcher article is dated May 4, with year contextualized by its 2026 fix timeline.
- Public Disclosure
- 2025-12-11explicit · Public competition demonstration; detailed technical publication followed in 2026.
Sources and provenance
- PostgreSQL text-encoding invariant failure caused memory corruption Wiz / ZeroDay.cloud · reviewed 2026-10-02
- Supporting primary disclosure source Wiz / ZeroDay.cloud · reviewed 2026-10-02
- Supporting primary disclosure source Paul Gerste, Moritz Sanft, Team Bugz Bunnies · reviewed 2026-10-02
- PostgreSQL CVE-2026-2006 vendor advisory PostgreSQL Global Development Group · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.