{"id":"CVE-2026-14664","title":"Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation","summary":"Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation.  This shares heritage with CVE-2026-2006, bu…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"postgresql","product":"postgresql","affected":["postgresql >= 14.0, < 14.24","postgresql >= 15.0, < 15.19","postgresql >= 16.0, < 16.15","postgresql >= 17.0, < 17.11","postgresql >= 18.0, < 18.5"],"patched":["postgresql 18.5"],"published":"2026-08-13","updated":"2026-08-29","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14664","references":[{"url":"https://www.postgresql.org/support/security/CVE-2026-14664/","label":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14664.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-14664"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2515311"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-14664"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-14664"},{"url":"https://access.redhat.com/errata/RHSA-2026:67280"},{"url":"https://access.redhat.com/errata/RHSA-2026:67491"},{"url":"https://access.redhat.com/errata/RHSA-2026:67848"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00436,"epssPercentile":0.37204,"ingestedAt":"2026-08-29T23:43:52.998Z","slug":"CVE-2026-14664","body":"## Overview\n\nHeap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation.  This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.\n\n## Affected\n\n- `postgresql >= 14.0, < 14.24`\n- `postgresql >= 15.0, < 15.19`\n- `postgresql >= 16.0, < 16.15`\n- `postgresql >= 17.0, < 17.11`\n- `postgresql >= 18.0, < 18.5`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `postgresql 18.5`\n\n## Vendor advisories\n\n- **RHSA-2026:67280** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67280)\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Self-service automation portal 2 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Self-service automation portal 2 · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14664.json)\n- **RHSA-2026:67491** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67491)\n- **RHSA-2026:67848** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67848)","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}