CVE-2026-14668
Executive Summary
CVE-2026-14668 exposes a type‑confusion flaw in PostgreSQL’s ctid selectivity estimator. An attacker can supply a non‑ctid input that causes the estimator to read an arbitrary 4‑byte memory span, leaking partial memory contents. The vulnerability affects PostgreSQL releases prior to 18.6, 17.11, 16.15, 15.19, and 14.24 and is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 8.1 (HIGH) - Published: 2026-08-13T13:17:44.137 - Last Modified: 2026-08-29T23:17:12.830
Original Description: Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
"Life is a learning experience, only if you learn."
— Yogi Berra