CVE-2026-102639
Received Received - Intake

Out-of-Bounds Read in MobilityDB PostgreSQL Extension

Vulnerability report for CVE-2026-102639, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

MobilityDB version 1.3.0 and earlier contains an out-of-bounds read vulnerability in the MEOS binary and library WKB deserialization logic that allows unprivileged database users to crash the PostgreSQL backend process by supplying a crafted WKB payload with a negative length field. The negative length value wraps to a large unsigned size_t due to missing signed validation, bypasses an overflow-unsafe pointer arithmetic bounds check in wkb_parse_state_check(), and causes memcpy() in text_from_wkb_state() to operate with a corrupted unbounded length, resulting in a remote denial-of-service condition affecting all sessions on the PostgreSQL instance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
mobilitydb mobilitydb 1.1.0
mobilitydb mobilitydb 1.1.1
mobilitydb mobilitydb 1.1.2
mobilitydb mobilitydb 1.2.0
mobilitydb mobilitydb 1.2.1
mobilitydb mobilitydb 1.2.2
mobilitydb mobilitydb 1.3.0
mobilitydb mobilitydb 1.3.1
mobilitydb mobilitydb to 1.3.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-195 The product uses a signed primitive and performs a cast to an unsigned primitive, which can produce an unexpected value if the value of the signed primitive can not be represented using an unsigned primitive.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds read vulnerability in MobilityDB versions 1.3.0 and earlier. It occurs when unprivileged database users supply a crafted WKB payload with a negative length field. The negative value bypasses bounds checks due to missing signed validation, causing a large unsigned size_t wrap-around. This leads to corrupted pointer arithmetic and a memcpy operation with an unbounded length, crashing the PostgreSQL backend process and causing a denial-of-service for all sessions.

Detection Guidance

Detecting this vulnerability requires checking the installed version of MobilityDB. Run 'SELECT extversion FROM pg_extension WHERE extname = "mobilitydb";' in PostgreSQL to verify if the version is 1.3.0 or earlier. If so, the system is vulnerable. Additionally, monitor PostgreSQL logs for crashes triggered by binary input functions like ttextFromBinary or ttextFromHexWKB.

Impact Analysis

An attacker with database access can exploit this to crash the PostgreSQL backend, disrupting all database sessions. This requires only access to binary input functions like ttextFromBinary or COPY ...BINARY. The impact is a denial-of-service affecting the entire PostgreSQL instance, not just the attacker's session.

Mitigation Strategies

Upgrade MobilityDB to version 1.3.1 or 1.2.2 immediately. After upgrading, run 'ALTER EXTENSION mobilitydb UPDATE TO "1.3.1";' in each PostgreSQL database. As a temporary workaround, revoke EXECUTE permissions on affected functions like ttextFromBinary from unnecessary roles until the upgrade is completed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102639. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart