{"id":"CVE-2026-102639","summary":"MobilityDB through 1.3.0 Out-of-bounds Read DoS via WKB Deserialization","details":"MobilityDB version 1.3.0 and earlier contains an out-of-bounds read vulnerability in the MEOS binary and library WKB deserialization logic that allows unprivileged database users to crash the PostgreSQL backend process by supplying a crafted WKB payload with a negative length field. The negative length value wraps to a large unsigned size_t due to missing signed validation, bypasses an overflow-unsafe pointer arithmetic bounds check in wkb_parse_state_check(), and causes memcpy() in text_from_wkb_state() to operate with a corrupted unbounded length, resulting in a remote denial-of-service condition affecting all sessions on the PostgreSQL instance.","aliases":["GHSA-2c92-2w7c-pm3g"],"modified":"2026-09-30T03:52:38.196672276Z","published":"2026-09-29T17:57:36.883Z","database_specific":{"cwe_ids":["CWE-195"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102639.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-102639.json"},{"type":"PACKAGE","url":"https://github.com/MobilityDB/MobilityDB"},{"type":"FIX","url":"https://github.com/MobilityDB/MobilityDB/releases/tag/v1.2.2"},{"type":"FIX","url":"https://github.com/MobilityDB/MobilityDB/releases/tag/v1.3.1"},{"type":"ADVISORY","url":"https://github.com/MobilityDB/MobilityDB/security/advisories/GHSA-2c92-2w7c-pm3g"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102639"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/mobilitydb-through-out-of-bounds-read-dos-via-wkb-deserialization"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mobilitydb/mobilitydb","events":[{"introduced":"e00c69f36a2948c4ad500dd98dfafc17fe46a8d2"},{"last_affected":"6088e7bc10a31dee34fbc3e3139288a218e4ec65"},{"introduced":"60048b5b4b7ce2f7560c024d1af024db73b3bd5b"},{"fixed":"f02cf5772a7c2f61fa729c29c333da7a45c4709e"},{"introduced":"8aa274c71a59170381fcf2ddef9d5907f3076e11"},{"fixed":"3bd6609ccf1b8f929e3988d40238c577cb8252a1"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.1.0"},{"last_affected":"1.1.2"},{"introduced":"1.2.0"},{"fixed":"1.2.2"},{"introduced":"1.3.0"},{"fixed":"1.3.1"}]}}],"versions":["v1.2.1","v1.3.0","v1.2.0","v1.1.2","v1.1.1","v1.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-102639.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}