CVE-2018-1058
PostgreSQL search_path privilege escalation: an unprivileged user can create objects that a superuser then executes
- Severity
- high
- Affected product
- PostgreSQL
- Affected versions
- PostgreSQL ≥ 10, < 10.3
- Affected versions
- PostgreSQL ≥ 9.6, < 9.6.8
- Affected versions
- PostgreSQL ≥ 9.5, < 9.5.12
- Affected versions
- PostgreSQL ≥ 9.4, < 9.4.17
- Affected versions
- PostgreSQL ≥ 9.3, < 9.3.22
- Fixed in
- PostgreSQL 10.3
- Fixed in
- PostgreSQL 9.6.8
- Fixed in
- PostgreSQL 9.5.12
- Fixed in
- PostgreSQL 9.4.17
- Fixed in
- PostgreSQL 9.3.22
- Added to NewScan
- 2026-08-10
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints PostgreSQL from its response and reports this CVE when the detected version falls inside the affected range below.
Range from the PostgreSQL project's own advisory page for CVE-2018-1058 (affected: 10 <10.3, 9.6 <9.6.8, 9.5 <9.5.12, 9.4 <9.4.17, 9.3 <9.3.22; all fixed 2018-03-01) - one row per branch because the matcher takes one interval per row. Proof pair: affected = training/cve vulhub postgres/CVE-2018-1058 (9.6.7, measured), fixed = the same corpus's 10.7 and training/tech/postgresql's 16.3, both measured clean. NOTE the version is only knowable AFTER authentication (both CVE envs demand md5, so an unauthenticated probe reads no version at all) - so this row fires on the credentialed posture path or on a `trust` server, never from a bare port scan.
COMPONENT VERSION RANGE
NewScan fingerprints PostgreSQL from its response and reports this CVE when the detected version falls inside the affected range below.
The 9.6 branch of CVE-2018-1058. See the 10.x row for the full advisory and proof pair.
COMPONENT VERSION RANGE
NewScan fingerprints PostgreSQL from its response and reports this CVE when the detected version falls inside the affected range below.
The 9.5 branch of CVE-2018-1058. See the 10.x row for the full advisory and proof pair.
COMPONENT VERSION RANGE
NewScan fingerprints PostgreSQL from its response and reports this CVE when the detected version falls inside the affected range below.
The 9.4 branch of CVE-2018-1058. See the 10.x row for the full advisory and proof pair.
COMPONENT VERSION RANGE
NewScan fingerprints PostgreSQL from its response and reports this CVE when the detected version falls inside the affected range below.
The 9.3 branch of CVE-2018-1058. See the 10.x row for the full advisory and proof pair. DELIBERATELY ABSENT from this key: CVE-2019-9193 (COPY TO/FROM PROGRAM). The PostgreSQL Security Team states it is 'not a security vulnerability' and that 'the CVE entry was filed in error' - COPY PROGRAM already requires superuser or pg_execute_server_program, and there is no security boundary between a database superuser and the OS user. A version row for it would fire on every 9.3-11 server on earth. training/cve registers the env (postgres-copy-rce) so the claim stays testable; it ships no row.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →