Splunk Enterprise

postgres update

SiddhatNegi
Engager

i am getting on vulnerability on one of the servers . how can i upgrade it.

SiddhatNegi_0-1776060583113.png

 

Labels (1)
0 Karma

kknairr
Contributor

@SiddhatNegi  As per your screenshot, the vulnerability is related to PostgreSQL which Splunk bundles as part of its internal services. To remediate the vulnerability, upgrade Splunk Enterprise version to the latest maintenance release that includes PostgreSQL 17.8. Please do not attempt to patch PostgreSQL separately as it's part of Splunk bundle and can cause issues. You can review the Splunk advisory and search for the respective CVE number. If you can share the CVE details and Splunk version you are running, we can assist further to locate the actual version to fix it.

Ref: Splunk Vulnerability Disclosure

>>

If this post addressed your question, you can:

  • Give it karma to show appreciation 👍
  • Mark it as the solution if it solved your issue ✔️
  • Add a comment if you’d like more details ✏️

Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.

>>

 

SiddhatNegi
Engager

so splunk version is 10.2.0

SiddhatNegi_0-1776088358053.png

hope this helps.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Check https://advisory.splunk.com and install the version of Splunk that fixes that vulnerability.

Do NOT attempt to patch postgres independently.

---
If this reply helps you, Karma would be appreciated.

SplunkNinja
Path Finder

@richgalloway 

I just upgraded to Splunk Enterprise 10.0.5 but I am still seeing the postgres vuln.  Do you know when postgres version 17.8 will be bundled with a new Splunk update?

Path : /opt/splunk/bin/postgres
Installed version : 17.7
Fixed version : 17.8

Third-Party Package Updates in Splunk Enterprise - April 2026

Package Remediation CVE Severity

protobuf1Upgraded protobuf to version 5.29.6CVE-2026-0994High
postgresql2Upgraded postgresql to version 17.7MultipleMedium
azure-core3Upgraded azure-core to version 1.38.0MultipleHigh
OpenSSL4Upgraded OpenSSL to version 1.0.2zoCVE-2026-22796Low
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk 10.0.x is not the latest version.  Try 10.2.x.

---
If this reply helps you, Karma would be appreciated.
0 Karma

SplunkNinja
Path Finder

From what I can see in the latest Third-Party Package Updates in Splunk Enterprise - April 2026

 2 Upgraded postgresql to version 17.7 to remedy CVE-2025-12817 and CVE-2025-12818 in Splunk Enterprise versions 10.2.2 and 10.0.5. Splunk Enterprise versions 9.4 and 9.3 are not affected

Seems like Splunk Enterprise versions 10.2.2 and 10.0.5 mitigate CVE-2025-12817 and CVE-2025-12818, but I am not seeing any mention of remediating CVE-2026-2004CVE-2026-2005, and CVE-2026-2006 in the latest Splunk Security Advisories.  I need to wait before updating and see which Splunk version brings postgres to version 17.8

0 Karma

nikhil14aug
Engager

What is wrong with addressing postgress directly? 

tar xf postgresql-17.8.tar.bz2
      cd postgresql-17.8
      yum install -y gcc readline-devel zlib-devel libicu-devel perl-FindBin
      ./configure --prefix=/opt/splunk
      make
      make install

this worked fine for me 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

We don't know what customizations Splunk may have made to postgres.  Installing code from another source may introduce incompatibilities.

Code not released by Splunk may not be supported by Splunk.

Changing delivered files may trigger File Integrity Check warnings.

---
If this reply helps you, Karma would be appreciated.
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...