VYPR
Vendor

Timescale

Products
5
CVEs
10
Across products
10
Status
Private

Products

5

Recent CVEs

10
  • CVE-2025-52467CriJun 19, 2025
    risk 0.52cvss 9.1epss 0.00

    pgai is a Python library that transforms PostgreSQL into a retrieval engine for RAG and Agentic applications. Prior to commit 8eb3567, the pgai repository was vulnerable to an attack allowing the exfiltration of all secrets used in one workflow. In particular, the GITHUB_TOKEN…

  • CVE-2026-70634HigAug 6, 2026
    risk 0.46cvss 8.1epss 0.01

    TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of…

  • CVE-2026-70635HigAug 6, 2026
    risk 0.39cvss 7.1epss 0.00

    TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed…

  • CVE-2026-81100MedAug 27, 2026
    risk 0.37cvss 6.8epss 0.00

    tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host…

  • CVE-2026-81099MedAug 27, 2026
    risk 0.37cvss 6.8epss 0.00

    tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it…

  • CVE-2026-81095MedAug 27, 2026
    risk 0.37cvss 6.8epss 0.00

    pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServer.ts called the shared httpServerFactory helper and never set the DNS-rebinding-protection option, so the transport accepted a request whatever host it named.…

  • CVE-2026-70633MedAug 6, 2026
    risk 0.35cvss 6.5epss 0.01

    TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator that allows authenticated attackers to cause a denial of service by storing a crafted compressed datum with an internally…

  • CVE-2026-29089HigMar 6, 2026
    risk 0.00cvss 8.8epss 0.00

    TimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From version 2.23.0 to 2.25.1, PostgreSQL uses the search_path setting to locate unqualified database objects (tables, functions, operators). If the search_path…

  • CVE-2023-25149HigFeb 14, 2023
    risk 0.00cvss 8.8epss 0.01

    TimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, TimescaleDB creates a telemetry job that is runs as the installation user. The queries run as part of the telemetry data…

  • CVE-2022-24128HigMar 13, 2022
    risk 0.00cvss 8.0epss 0.01

    Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer…