PT-2026-71472 · Postgresql Global Development Group+2 · Postgresql+2

CVE-2026-14676

·

Published

2026-08-12

·

Updated

2026-09-03

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 18.0 through 18.4
Description A heap buffer overflow exists in the pg stat statements module. This issue allows a query author to execute arbitrary code with the privileges of the operating system user running the database by using specially crafted queries that contain array constants.
Recommendations Update PostgreSQL to version 18.5 or later.

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11960
BIT-POSTGRESQL-2026-14676
CVE-2026-14676
OPENSUSE-SU-2026:11565-1
OPENSUSE-SU-2026:21703-1
SUSE-SU-2026:3942-1
USN-8653-1

Affected Products

Linuxmint
Postgresql
Ubuntu