Root cause
Cryptographic message parsing copied a derived key length into a fixed-capacity destination without verifying that the destination was large enough.
Demonstrated impact
The PostgreSQL advisory confirms possible code execution under the database operating-system account. The vendor CVE record limits the prerequisite to permission to install the extension or supply ciphertext to an existing installation.
Lessons for review
- Validate derived lengths against destination capacity before copying data.
- Review extension permissions and least-privilege database process identities.
- Use vendor release evidence to verify remediation rather than replaying an exploit.
Award and evidence
One entry award, excluding the team’s other database entries. The results use $; USD denomination is contextualized by the organizer’s current rules, which concern 2026 rather than an archived 2025 rules snapshot. No conversion or cash-settlement claim is made.
Read the named researcher report, organizer CVE tracker and per-entry award result; cross-checked vendor advisories and CNA records. Currency context is explicitly distinguished from award evidence. No vulnerability testing performed.
- The event demonstration is distinct from the February 12, 2026 vendor advisory and May research article.
- The source identifies Team Xint Code; no allocation to named individual recipients is established.
- The article shows May 4 without a year; 2026 is inferred from its explicitly dated remediation timeline.
- Exact award decision and funds-transfer dates are not reported; December 16 is the dated organizer announcement.
- Current rules establish program US-dollar notation but are not an archived snapshot of the 2025 rules.
Recorded timeline
- Published
- 2026-05-04inferred · Displayed May 4; year inferred from the completed 2026 remediation timeline.
- Public Disclosure
- 2025-12-10explicit · Public competition demonstration. Subsequent CVE/advisory publication and full technical article are separate events.
- Fixed
- 2026-02-12explicit · Vendor patch release, not proof of deployment by every customer.
- Award Announced
- 2025-12-16explicit · Dated organizer recap announces the exact entry award; decision and transfer dates remain unknown.
Sources and provenance
- CVE-2026-2005: PostgreSQL pgcrypto heap buffer overflow leading to RCE Team Xint Code / ZeroDay.cloud · reviewed 2026-10-02
- ZeroDay.cloud 2025 individual competition results Nir Ohfeld / Wiz Research · reviewed 2026-10-02
- ZeroDay.cloud vulnerability tracker Wiz / ZeroDay.cloud · reviewed 2026-10-02
- ZeroDay.cloud current rules: US-dollar denomination Wiz · reviewed 2026-10-02
- PostgreSQL CVE-2026-2005 security advisory PostgreSQL · reviewed 2026-10-02
- CVE-2026-2005 CNA record PostgreSQL CNA / CVE Program · reviewed 2026-10-02
Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.