Known Vulnerabilities for Postgres-mcp by Crystaldba
Listed below are 10 of the newest known vulnerabilities associated with "Postgres-mcp" by "Crystaldba".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-96883 json | pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might ... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-93594 json | ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules o... | Not Provided | 2026-09-18 | 2026-09-18 |
| CVE-2026-87911 json | An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-85787 json | An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version... | Not Provided | 2026-09-04 | 2026-09-08 |
| CVE-2026-85620 json | Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to Range... | Not Provided | 2026-09-04 | 2026-09-14 |
| CVE-2026-82752 json | Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of ar... | Not Provided | 2026-09-05 | 2026-09-08 |
| CVE-2026-82028 json | Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTTP API services ... | Not Provided | 2026-09-14 | 2026-09-16 |
| CVE-2026-76240 json | stigmem-node 0.9.0a1 interpolates Postgres backend schema identifiers into SQL strings without defensive quoting. In the affe... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-72862 json | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the mariadb.ts, mongo.ts, mysql.ts, postgres... | Not Provided | 2026-08-10 | 2026-08-13 |
| CVE-2026-72733 json | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscr... | Not Provided | 2026-08-10 | 2026-09-21 |