๐Ÿ” CVE Alert

CVE-2026-70635

HIGH 7.1

TimescaleDB 2.29.1 Out-of-Bounds Read DoS via Bulk Dictionary Decompression Negative Index

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with direct DML access to a non-frozen physical compressed hypertable relation can trigger an out-of-bounds read before the base of the live offsets array through the VectorAgg single-text hashing strategy, resulting in incorrect aggregation output, backend SIGSEGV, or PostgreSQL crash recovery depending on build configuration.

CWE CWE-129 CWE-125
Vendor timescale
Product timescaledb
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for timescale timescaledb

Be the first to know when new high vulnerabilities affecting timescale timescaledb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High

Affected Versions

timescale / timescaledb
0 โ‰ค 2.29.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/timescale/timescaledb/pull/10360 github.com: https://github.com/timescale/timescaledb/commit/517c13e7cc6afadb4a7deaa7a5a5a29065e5b5a3

Credits

Mehmet Ince (@mdisec)