CVE-2026-14664: PostgreSQL regexp heap buffer overflow executes arbitrary code
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pgwchar. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 18.5 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 17.11 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 16.15 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 15.19 - Upgrade
Upgrade
PostgreSQLto a version that resolves this vulnerability.Fixed in 14.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14664?
CVE-2026-14664 has a high severity rating of 8.8.
How do I fix CVE-2026-14664?
To fix CVE-2026-14664, you should update PostgreSQL to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-14664?
CVE-2026-14664 is a heap buffer overflow vulnerability in PostgreSQL.
What potential impact does CVE-2026-14664 have?
CVE-2026-14664 allows an attacker to execute arbitrary code as the operating system user running the PostgreSQL database.
Which software is affected by CVE-2026-14664?
The PostgreSQL software is affected by CVE-2026-14664.