Researchers disclosed an integer wraparound/overflow flaw in PostgreSQL’s libpq client library (tracked as CVE-2025-12818) that can be triggered via the PQescapeInternal code path used by PQescapeLiteral and PQescapeIdentifier. When a crafted input string of certain lengths includes quotes and/or backslashes, libpq can miscalculate the required buffer size, allocate too little memory, and then perform an out-of-bounds write by hundreds of megabytes, typically resulting in a segmentation fault (DoS) in the consuming application.
F5’s product advisories state that PostgreSQL versions prior to 18.1, 17.7, 16.11, 15.15, 14.20, and 13.23 are affected by CVE-2025-12818, but report no impact to F5 products after evaluation. Separate F5 advisories published alongside this disclosure cover unrelated issues, including a PostgreSQL authorization/DoS issue in CREATE STATISTICS (CVE-2025-12817), a curl cross-protocol redirect token-leak issue (CVE-2025-14524), an Apache Solr create core input-validation/allowPaths bypass with potential NTLM hash disclosure on Windows (CVE-2026-22444), and a local privilege-escalation issue in the Intel 800 Series Ethernet Linux driver affecting certain F5 appliance lines (CVE-2025-24325).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Positive Technologies published a detailed write-up showing how the libpq integer overflow can be triggered with extremely long escaped input and demonstrated escalation to an application-layer crash through PHP's pdo_pgsql driver.
F5 published a product advisory referencing PostgreSQL vulnerability CVE-2025-12818, indicating downstream vendor awareness and guidance related to the issue.
PostgreSQL released a security advisory for CVE-2025-12818, describing a denial-of-service issue in the libpq client library and listing patched versions across supported branches.
PostgreSQL published a fix in the postgres/postgres repository for an integer overflow in libpq's PQescapeInternal function that can lead to an undersized allocation and out-of-bounds write, tracked as CVE-2025-12818.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.