address_standardizer vulnerability

PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array, causing the PostgreSQL backend process to crash and terminate all cluster sessions.

Published 13 Sep 2026Updated 13 Sep 20268 sources
CVSS 7.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.