VendorsTimescaletimescaledbany version
Vulnerabilities

Timescale Timescaledb any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-25149
TimescaleDB has incorrect access control
Published 2023-02-14 · Modified
8.8EPSS 0.008
CVE-2026-29089
TimescaleDB uses untrusted search path during extension upgrade
Published 2026-03-06 · Analyzed
8.8EPSS 0.002
CVE-2026-70634
TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary Compression Reverse Iterator
Published 2026-08-06 · Analyzed
8.1EPSS 0.005
CVE-2022-24128
Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer (which executes as Superuser), leading to privilege escalation. In order to be able to take advantage of this, an unprivileged user would need to be able to create objects in a database and then get a Superuser to install TimescaleDB into their database. (In the fixed versions, the installation aborts when it finds that an object already exists.)
Published 2022-03-13 · Modified
8.0EPSS 0.009
CVE-2026-70633
TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Gorilla Compression Reverse Iterator
Published 2026-08-06 · Analyzed
7.1EPSS 0.005
CVE-2026-70635
TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression Negative Index
Published 2026-08-06 · Analyzed
7.1EPSS 0.004