CVE-2025-4207 - CVE House
Back to Database
Status published Medium CVE-2025-4207

PostgreSQL GB18030 encoding validation can read one byte past end of allocation for text that fails validation

Vulnerability Description

Buffer over-read in PostgreSQL GB18030 encoding validation allows a database input provider to achieve temporary denial of service on platforms where a 1-byte over-read can elicit process termination. This affects the database server and also libpq. Versions before PostgreSQL 17.5, 16.9, 15.13, 14.18, and 13.21 are affected.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-4207

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

PostgreSQL
Vulnerable Versions:
17, 16, 15, 14, 0

Timeline

Official Publish: May 8th, 2025
Last Modified: May 9th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)