๐Ÿ” CVE Alert

CVE-2026-14676

HIGH 8.8

PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.

CWE CWE-122
Vendor n/a
Product postgresql
Ecosystems
Industries
Technology
Published Aug 13, 2026
Stay Ahead of the Next One

Get instant alerts for n/a postgresql

Be the first to know when new high vulnerabilities affecting n/a postgresql are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / PostgreSQL
18 < 18.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
postgresql.org: https://www.postgresql.org/support/security/CVE-2026-14676/

Credits

The PostgreSQL project thanks Sajeeb Lohani (with TrendAI Zero Day Initiative), Yuelin Wang, and David Korczynski (Claude and Ada Logics) for reporting this problem.