---
id: CVE-2026-96883
title: pgcollection is an open source extension to PostgreSQL
summary: >-
  pgcollection is an open source extension to PostgreSQL. A type confusion issue
  in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote
  user to execute arbitrary code as the postgres operating system user via
  crafted S…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-843
vendor: AWS
product: pgcollection
affected:
  - pgcollection >= 2.0.0 <= 2.1.1
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:17:35.240'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96883'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-118-aws/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/aws/pgcollection/releases/tag/v2.1.2'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://github.com/aws/pgcollection/security/advisories/GHSA-g539-cj32-hv6r
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-24T19:26:07.145601Z'
ingestedAt: '2026-09-24T19:50:30.730Z'
---

## Overview

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions.



To remediate this issue, users should upgrade to version 2.1.2 or later.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
