Out-of-bounds Write Vulnerability in pgvector by Pgvector Team
CVE-2026-103484
8.8HIGH
What is CVE-2026-103484?
The IVFFlat index build in pgvector before version 0.8.7 contains a vulnerability that allows database users to write data out-of-bounds. This security flaw can be exploited to execute arbitrary code, impacting the integrity of the database and potentially compromising sensitive data. Users are advised to upgrade to the latest version to mitigate this risk effectively.
Affected Version(s)
pgvector 0 < 0.8.7
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks to Emanuele Barbeno, Cyrill Bannwart, Urs Mueller, and Lukasz D of Compass Security for reporting this.
