Ghostwire

CVE-2026-14676: Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating...

HIGH CVSS 0.0

Published: August 13, 2026 | Last Modified: August 13, 2026

Description

Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.

Ghostwire Analysis — What This Means Practically

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References