---
id: CVE-2026-14662
title: >-
  Integer wraparound in PostgreSQL tsvector and tsquery data type functions
  allows an unprivileged database user to cause the server to undersize an
  allocation and write out-of-bounds, via crafted large inputs
summary: >-
  Integer wraparound in PostgreSQL tsvector and tsquery data type functions
  allows an unprivileged database user to cause the server to undersize an
  allocation and write out-of-bounds, via crafted large inputs.  This may
  execute arbitrary …
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
  - CWE-787
vendor: postgresql
product: postgresql
affected:
  - 'postgresql >= 14.0, < 14.24'
  - 'postgresql >= 15.0, < 15.19'
  - 'postgresql >= 16.0, < 16.15'
  - 'postgresql >= 17.0, < 17.11'
  - 'postgresql >= 18.0, < 18.5'
patched:
  - postgresql 18.5
published: '2026-08-13'
updated: '2026-08-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14662'
references:
  - url: 'https://www.postgresql.org/support/security/CVE-2026-14662/'
    label: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14662.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-14662'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2515302'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-14662'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14662'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67280'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67491'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67848'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69698'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70186'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69923'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69876'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69914'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69607'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69924'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70602'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70763'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70762'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70856'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70559'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71603'
tags:
  - nvd
  - exploit-available
  - csaf
  - vex
  - red-hat
epss: 0.0046
epssPercentile: 0.37207
ingestedAt: '2026-08-29T23:43:52.870Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Kihara-1/postgresql-cve-2026-14662'
  checkedAt: '2026-09-26T09:05:38.125Z'
exploitAvailable: true
---

## Overview

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs.  This may execute arbitrary code as the operating system user running the database.  These types are typically sourced from application logic, not taken from the application's user.  Hence, application users attacking the database, through the application as a conduit, are unlikely.  CVE-2026-6473 had fixed similar problems.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

## Affected

- `postgresql >= 14.0, < 14.24`
- `postgresql >= 15.0, < 15.19`
- `postgresql >= 16.0, < 16.15`
- `postgresql >= 17.0, < 17.11`
- `postgresql >= 18.0, < 18.5`

## Remediation

Upgrade past the affected range:

- `postgresql 18.5`

## Vendor advisories

- **RHSA-2026:67280** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67280)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Self-service automation portal 2 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Self-service automation portal 2 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14662.json)
- **RHSA-2026:67491** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67491)
- **RHSA-2026:67848** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67848)
- **RHSA-2026:69698** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:69698)
- **RHSA-2026:70186** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70186)
- **RHSA-2026:69923** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69923)
- **RHSA-2026:69876** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69876)
- **RHSA-2026:69914** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69914)
- **RHSA-2026:69607** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69607)
- **RHSA-2026:69924** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:69924)
- **RHSA-2026:70602** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70602)
- **RHSA-2026:70763** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70763)
- **RHSA-2026:70762** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70762)
- **RHSA-2026:70856** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70856)
- **RHSA-2026:70559** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70559)
