CVE-2026-14676

EUVD-2026-57840
Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants.  Within major version 18, minor versions before PostgreSQL 18.5 are affected.  Versions before PostgreSQL 18 are unaffected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
postgresql-13
bullseye
13.16-0+deb11u1
fixed
bullseye (security)
13.23-0+deb11u4
fixed
postgresql-15
bookworm
15.18-0+deb12u1
fixed
bookworm (security)
15.19-0+deb12u1
fixed
postgresql-17
trixie
17.10-0+deb13u1
fixed
trixie (security)
17.11-0+deb13u1
fixed
postgresql-18
forky
vulnerable
sid
vulnerable