vulns.co
/
GKData.io MCP

MEMemory safety and parser contracts · 2 min read

PostgreSQL cryptographic parsing omitted a buffer-capacity check

The organizer awarded Team Xint Code USD 30,000 for this individually identified ZeroDay.cloud 2025 competition entry.

Read the primary source MEMemory safety and parser contractsReviewed 2026-10-02

Root cause

Cryptographic message parsing copied a derived key length into a fixed-capacity destination without verifying that the destination was large enough.

Demonstrated impact

The PostgreSQL advisory confirms possible code execution under the database operating-system account. The vendor CVE record limits the prerequisite to permission to install the extension or supply ciphertext to an existing installation.

Lessons for review

  • Validate derived lengths against destination capacity before copying data.
  • Review extension permissions and least-privilege database process identities.
  • Use vendor release evidence to verify remediation rather than replaying an exploit.

Award and evidence

USD 30,000Competition Award · Organizer Confirmed

One entry award, excluding the team’s other database entries. The results use $; USD denomination is contextualized by the organizer’s current rules, which concern 2026 rather than an archived 2025 rules snapshot. No conversion or cash-settlement claim is made.

Read the named researcher report, organizer CVE tracker and per-entry award result; cross-checked vendor advisories and CNA records. Currency context is explicitly distinguished from award evidence. No vulnerability testing performed.

  • The event demonstration is distinct from the February 12, 2026 vendor advisory and May research article.
  • The source identifies Team Xint Code; no allocation to named individual recipients is established.
  • The article shows May 4 without a year; 2026 is inferred from its explicitly dated remediation timeline.
  • Exact award decision and funds-transfer dates are not reported; December 16 is the dated organizer announcement.
  • Current rules establish program US-dollar notation but are not an archived snapshot of the 2025 rules.

Recorded timeline

Published
2026-05-04inferred · Displayed May 4; year inferred from the completed 2026 remediation timeline.
Public Disclosure
2025-12-10explicit · Public competition demonstration. Subsequent CVE/advisory publication and full technical article are separate events.
Fixed
2026-02-12explicit · Vendor patch release, not proof of deployment by every customer.
Award Announced
2025-12-16explicit · Dated organizer recap announces the exact entry award; decision and transfer dates remain unknown.

Sources and provenance

  1. CVE-2026-2005: PostgreSQL pgcrypto heap buffer overflow leading to RCE Team Xint Code / ZeroDay.cloud · reviewed 2026-10-02
  2. ZeroDay.cloud 2025 individual competition results Nir Ohfeld / Wiz Research · reviewed 2026-10-02
  3. ZeroDay.cloud vulnerability tracker Wiz / ZeroDay.cloud · reviewed 2026-10-02
  4. ZeroDay.cloud current rules: US-dollar denomination Wiz · reviewed 2026-10-02
  5. PostgreSQL CVE-2026-2005 security advisory PostgreSQL · reviewed 2026-10-02
  6. CVE-2026-2005 CNA record PostgreSQL CNA / CVE Program · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software