CVE-2026-102639 Details
Description
MobilityDB version 1.3.0 and earlier contains an out-of-bounds read vulnerability in the MEOS binary and library WKB deserialization logic that allows unprivileged database users to crash the PostgreSQL backend process by supplying a crafted WKB payload with a negative length field. The negative length value wraps to a large unsigned size_t due to missing signed validation, bypasses an overflow-unsafe pointer arithmetic bounds check in wkb_parse_state_check(), and causes memcpy() in text_from_wkb_state() to operate with a corrupted unbounded length, resulting in a remote denial-of-service condition affecting all sessions on the PostgreSQL instance.
A denial-of-service vulnerability has been identified in MobilityDB versions through 1.3.0. The issue arises from an out-of-bounds read in the Well-Known Binary (WKB) deserialization process, which is used for temporal, set, and span values. Unprivileged database users can exploit this vulnerability by sending a crafted WKB payload with a negative length field, causing the PostgreSQL backend process to crash. The negative length wraps to a large unsigned value due to inadequate validation, bypasses a bounds check in the WKB parsing function, and leads to a memory copy operation with an incorrect, unbounded length. This exploitation creates a remote denial-of-service condition that affects all sessions on the PostgreSQL instance.
Users can upgrade to MobilityDB versions 1.2.2 or 1.3.1. After upgrading, run 'ALTER EXTENSION mobilitydb UPDATE TO [version];' in each database to complete the update process.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/MobilityDB/MobilityDB/releases/tag/v1.2.2 | [email protected] | Release NotesVendor |
| https://github.com/MobilityDB/MobilityDB/releases/tag/v1.3.1 | [email protected] | Release NotesVendor |
| https://github.com/MobilityDB/MobilityDB/security/advisories/GHSA-2c92-2w7c-pm3g | [email protected] | AdvisoryRemedyVendor |
| https://www.vulncheck.com/advisories/mobilitydb-through-out-of-bounds-read-dos-via-wkb-deserialization | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-195 | Signed to Unsigned Conversion Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| MobilityDB | >= 1.3.0, < 1.3.1 (semver) >= 1.2.0, < 1.2.2 (semver) >= 1.1.0, <= 1.1.2 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion