Out-of-bounds Write Vulnerability in pgvector by Pgvector Team
CVE-2026-103484

8.8HIGH

Key Information:

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-103484?

The IVFFlat index build in pgvector before version 0.8.7 contains a vulnerability that allows database users to write data out-of-bounds. This security flaw can be exploited to execute arbitrary code, impacting the integrity of the database and potentially compromising sensitive data. Users are advised to upgrade to the latest version to mitigate this risk effectively.

Affected Version(s)

pgvector 0 < 0.8.7

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks to Emanuele Barbeno, Cyrill Bannwart, Urs Mueller, and Lukasz D of Compass Security for reporting this.
.