CVE-2025-12817 - CVE House
Back to Database
Status published Low CVE-2025-12817

PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege

Vulnerability Description

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS users by creating in any schema. A later CREATE STATISTICS for the same name, from a user having the CREATE privilege, would then fail. Versions before PostgreSQL 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-12817

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • The PostgreSQL project thanks Jelte Fennema-Nio for reporting this problem.

Affected Vendor

Affected Software

PostgreSQL
Vulnerable Versions:
18, 17, 16, 15, 14, 0

Timeline

Official Publish: November 13th, 2025
Last Modified: November 13th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

Weaknesses (CWE)