CVE-2026-103484: pgvector buffer overflow in IVFFlat index build
Published Oct 1, 2026
·Updated
IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
Affected Software
1 affected component
pgvector pgvector<0.8.7
Event History
Oct 1, 2026
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this vulnerability?
An authenticated database user can exploit it. The supplied severity vector indicates network-reachable exploitation with low attack complexity and no user interaction, but low privileges are required.
2
Which installations are affected?
pgvector versions before 0.8.7 are affected when building an IVFFlat index. The provided data does not state whether IVFFlat indexing is enabled or used by default.
3
What is the potential impact?
An attacker may perform an out-of-bounds write during IVFFlat index build, potentially leading to arbitrary code execution. Confidentiality, integrity, and availability impacts are all rated high.