CVE-2026-14677EPSS p34.4%
CVE-2026-14677CVE-2026-14677
postgresql / postgresql
Description
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.
Scoring
| CVSS | 8.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.42% probability of exploitation · percentile 34.4% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-29 |