CVE-2026-14662

Executive Summary

Integer wraparound in PostgreSQL’s tsvector/tsquery functions allows an unprivileged database user to trigger an out‑of‑bounds write by supplying crafted large inputs. The undersized allocation can lead to arbitrary code execution as the database OS user. The flaw is present in PostgreSQL 18.6 and earlier, 17.11 and earlier, 16.15 and earlier, 15.19 and earlier, and 14.24 and earlier. It is similar to CVE‑2026‑6473, which addressed related wraparound issues.


Authoritative CVE Metadata - CVSS Base Score: 8.8 (HIGH) - Published: 2026-08-13T13:17:43.553 - Last Modified: 2026-08-29T23:17:11.010

Original Description: Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

"Fate is in your hands and no one elses"

— Byron Pulsifer
Source: NVD