CVE-2026-14664

Executive Summary

Heap buffer overflow in PostgreSQL’s regular expression engine allows a query author to execute arbitrary code as the database’s OS user. The flaw is triggered by specially crafted text that bypasses encoding validation and causes unexpected data growth when round‑tripped through pg_wchar. Versions prior to PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are vulnerable. The issue is not yet listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 8.8 (HIGH) - Published: 2026-08-13T13:17:43.847 - Last Modified: 2026-08-29T23:17:11.963

Original Description: Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

"Let us revere, let us worship, but erect and open-eyed, the highest, not the lowest; the future, not the past!"

— Charlotte Gilman
Source: NVD