A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
Conclusion & alert: CVE-2021-3677 is rated Moderate Risk (51.4/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.43%). Core evidence: EPSS rose +1.17% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.25% | 1.43% | +1.17% |
| 2 | 2026-05-07 | 0.19% | 0.25% | +0.06% |
| 3 | 2025-11-21 | — | 0.19% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 4.0 | 2.0 | MEDIUM |
|
8.0 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
medium | CVE-2021-3677: 5 source package rows (postgresql, postgresql12, postgresql13, postgresql14, postgresql15); 32 state rows across 12 repos (3.11-main, 3.12-main, 3.17-community, 3.17-main, 3.18-community, 3.18-main, 3.19-community, 3.19-main, 3.20-community, 3.20-main, edge-community, edge-main); fixed 23, open 9. | https://security.alpinelinux.org/vuln/CVE-2021-3677 |
debian
|
not yet assigned | CVE-2021-3677 not yet assigned priority: Debian including 1 source packages (postgresql-13), 1 status rows across 1 suites (bullseye): resolved 1. | https://security-tracker.debian.org/tracker/CVE-2021-3677 |
gentoo
|
high | CVE-2021-3677: 1 GLSA(s) (202211-04), 1 atom(s) (dev-db/postgresql); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2021-3677 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2021-3677 |
suse
|
medium | CVE-2021-3677 severity moderate: SUSE including 405 source package names (10.19:libpq5-13.4-5.16.2, 12-5.1:libpq5-13.4-5.16.2, …), 1190 product×package rows across 91 product lines (Container suse/postgres, Container trento/trento-db, … (91 product lines)): Known Not Affected 544, Fixed 415, Known Affected 231. | https://www.suse.com/security/cve/CVE-2021-3677/ |
ubuntu
|
medium | CVE-2021-3677 medium priority: Ubuntu including 6 source packages (postgresql-10, postgresql-12, postgresql-13, postgresql-9.1, postgresql-9.3, postgresql-9.5), 48 status rows across 8 suites (bionic, focal, hirsute, impish, jammy, trusty, upstream, xenial): DNE 36, not-affected 7, released 5. | https://ubuntu.com/security/CVE-2021-3677 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| postgresql | postgresql | >= 11.0, < 11.13 | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
| postgresql | postgresql | >= 12.0, < 12.8 | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
| postgresql | postgresql | >= 13.0, < 13.4 | cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:* |
| redhat | virtualization | 4.0 | cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux | 8.0 | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_ibm_z_systems | 8.0 | cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:8.0:*:*:*:*:*:*:* |
| redhat | enterprise_linux_for_power_little_endian | 8.0 | cpe:2.3:o:redhat:enterprise_linux_for_power_little_endian:8.0:*:*:*:*:*:*:* |
| redhat | software_collections | 1.0 | cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:* |
| fedoraproject | fedora | 34 | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2001857 | Issue Tracking Third Party Advisory |
| https://security.gentoo.org/glsa/202211-04 | Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20220407-0008/ | Third Party Advisory |
| https://www.postgresql.org/support/security/CVE-2021-3677/ | Vendor Advisory |