---
id: CVE-2026-14679
title: >-
  Stack buffer overflow in PostgreSQL argument name matching allows an object
  creator to achieve unknown impacts via OUT parameter count
summary: >-
  Stack buffer overflow in PostgreSQL argument name matching allows an object
  creator to achieve unknown impacts via OUT parameter count.  The attack can
  write only 0x0 and 0x1 bytes.  Versions before PostgreSQL 18.6, 17.11, 16.15,
  15.19, …
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'
cwe:
  - CWE-121
vendor: postgresql
product: postgresql
affected:
  - 'postgresql >= 14.0, < 14.24'
  - 'postgresql >= 15.0, < 15.19'
  - 'postgresql >= 16.0, < 16.15'
  - 'postgresql >= 17.0, < 17.11'
  - 'postgresql >= 18.0, < 18.5'
patched:
  - postgresql 18.5
published: '2026-08-13'
updated: '2026-08-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14679'
references:
  - url: 'https://www.postgresql.org/support/security/CVE-2026-14679/'
    label: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14679.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-14679'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2515321'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-14679'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14679'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67280'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67491'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67848'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70186'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69923'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69876'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69914'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69607'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69924'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70602'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70762'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70856'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70559'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71603'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.00293
epssPercentile: 0.19617
ingestedAt: '2026-08-29T23:43:53.459Z'
scores:
  nvd: 8.2
  vendor: 7.1
---

## Overview

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count.  The attack can write only 0x0 and 0x1 bytes.  Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

## Affected

- `postgresql >= 14.0, < 14.24`
- `postgresql >= 15.0, < 15.19`
- `postgresql >= 16.0, < 16.15`
- `postgresql >= 17.0, < 17.11`
- `postgresql >= 18.0, < 18.5`

## Remediation

Upgrade past the affected range:

- `postgresql 18.5`

## Vendor advisories

- **RHSA-2026:67280** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67280)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Self-service automation portal 2 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Self-service automation portal 2 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-14679.json)
- **RHSA-2026:67491** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67491)
- **RHSA-2026:67848** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:67848)
- **RHSA-2026:70186** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:70186)
- **RHSA-2026:69923** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69923)
- **RHSA-2026:69876** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69876)
- **RHSA-2026:69914** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69914)
- **RHSA-2026:69607** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-09-22 · [advisory](https://access.redhat.com/errata/RHSA-2026:69607)
- **RHSA-2026:69924** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:69924)
- **RHSA-2026:70602** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70602)
- **RHSA-2026:70762** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70762)
- **RHSA-2026:70856** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70856)
- **RHSA-2026:70559** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70559)
