PT-2026-65883 · Pgvector · Pgvector

·

CVE-2026-18022

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pgvector versions prior to 0.8.6
Description An integer wraparound occurs during the IVFFlat index build process on 32-bit systems. This issue allows a database user to perform an out-of-bounds write, which could potentially lead to arbitrary code execution. Integer wraparound is a condition where an arithmetic operation results in a value too large for the designated integer type, causing it to wrap around to a minimum or negative value.
Recommendations Update pgvector to version 0.8.6 or later.

Exploit

Fix

Integer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18022
ECHO-7790-2EA8-7D0B

Affected Products

Pgvector