PT-2026-68791 · Postgresql Global Development Group+1 · Postgresql+1

·

CVE-2026-70635

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions TimescaleDB versions prior to 2.29.1
Description An out-of-bounds read occurs when authenticated attackers provide a crafted Simple8b selector-11 value. This value is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks during bulk text dictionary decompression. Attackers with direct DML (Data Manipulation Language) access to a non-frozen physical compressed hypertable relation can trigger this read before the base of the live offsets array using the VectorAgg single-text hashing strategy. This can lead to query-result integrity failures, incorrect aggregation output, backend SIGSEGV (a segmentation fault), or PostgreSQL crash recovery.
Recommendations Update TimescaleDB to version 2.29.1 or later to apply the fix implemented in commit 517c13e.

Exploit

Fix

Out of bounds Read

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70635

Affected Products

Postgresql
Timescaledb