PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 0.5%
from disclosure to weapon19 days
Published on NVDAug 13
1st PoC+19d
exploitation probability
0.5%top 62% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · PostgreSQLpublic PoCs found — 1
githubgithub.com/Kihara-1/postgresql-cve-2026-14662★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.