VDB

CVE-2026-14664

CVE-2026-14664 PUBLISHED CVSS 8.8 HIGH

Reported by PostgreSQL · Published August 13, 2026

Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Risk Scores

CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
n/aPostgreSQL18, 17, 16
alpinepostgresql150, 0, 0
alpinepostgresql170, 0, 0
n/aPostgreSQL18, 17, 16
alpinepostgresql180, 0, 0
alpinepostgresql160, 0, 0

Timeline

  • Aug 13, 2026 CVE Published
  • Aug 15, 2026 Coalition ESS Score
  • Aug 20, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 14, 2026 Distribution Patch
  • Sep 14, 2026 Security Advisory

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›