CVE-2026-14669: PostgreSQL to_char heap buffer overflow executes arbitrary code
Heap buffer overflow in PostgreSQL tochar(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.5 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 16.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 15.19 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 14.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14669?
CVE-2026-14669 has a high severity rating of 8.8.
How do I fix CVE-2026-14669?
To mitigate CVE-2026-14669, upgrade PostgreSQL to version 18.5, 17.11, 16.15, 15.19, or 14.24.
What is the impact of CVE-2026-14669?
CVE-2026-14669 allows arbitrary code execution as the operating system user running the database due to a heap buffer overflow.
Which PostgreSQL versions are affected by CVE-2026-14669?
Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are vulnerable to CVE-2026-14669.
What type of vulnerability is CVE-2026-14669?
CVE-2026-14669 is classified as a buffer overflow vulnerability.