Heap Buffer Overflow in PostgreSQL Affects Multiple Versions
CVE-2026-14669
8.8HIGH
What is CVE-2026-14669?
A heap buffer overflow vulnerability in PostgreSQL affects the to_char(timestamptz) function. This issue arises when long POSIX timezone abbreviations are used, potentially allowing an attacker to execute arbitrary code as the operating system user running the database. This vulnerability poses significant risks to systems running affected versions of PostgreSQL, making it essential for administrators to update to the latest versions to mitigate potential exploitation.
Affected Version(s)
PostgreSQL 18 < 18.5
PostgreSQL 17 < 17.11
PostgreSQL 16 < 16.15
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The PostgreSQL project thanks Hcamael, Amjad Shahzad, Tomer Fichman, Zheng Yu, Amy Burnett (OpenAI Codex Security), Rick de Jager, Heewon Song, Sylvie Mayer, Aleksander Alekseev, and Hillai Ben Sasson for reporting this problem.