CVE-2026-102639: high-severity vulnerability in MobilityDB
MobilityDB through 1.3.0 Out-of-bounds Read DoS via WKB Deserialization
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.3%
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
nono source reports it
MobilityDB version 1.3.0 and earlier contains an out-of-bounds read vulnerability in the MEOS binary and library WKB deserialization logic that allows unprivileged database users to crash the PostgreSQL backend process by supplying a crafted WKB payload with a negative length field. The negative length value wraps to a large unsigned size_t due to missing signed validation, bypasses an overflow-unsafe pointer arithmetic bounds check in wkb_parse_state_check(), and causes memcpy() in text_from_wkb_state() to operate with a corrupted unbounded length, resulting in a remote denial-of-service condition affecting all sessions on the PostgreSQL instance.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
MobilityDB · MobilityDBReferences
https://github.com/MobilityDB/MobilityDB/releases/tag/v1.2.2https://github.com/MobilityDB/MobilityDB/releases/tag/v1.3.1https://github.com/MobilityDB/MobilityDB/security/advisories/GHSA-2c92-2w7c-pm3ghttps://www.vulncheck.com/advisories/mobilitydb-through-out-of-bounds-read-dos-via-wkb-deserialization