CVE-2026-14676

Published: August 18, 2026Last modified: August 24, 2026

Description

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.

Severity score breakdown

ParameterValue
Base score8.8
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSpostgresql15Unknown (15.2-r0)
25 LTSpostgresql17Fixed (17.11-r0)
Streampostgresql15Unknown (15.3-r0)
postgresql17Unknown (17.0-r1)
postgresql18Fixed (18.6-r0)

References

ON THIS PAGE