CVE-2026-14670: PostgreSQL plperl tied object heap buffer overflow executes arbitrary code
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PostgreSQL plperlto a version that resolves this vulnerability.Fixed in 18.5 - Upgrade
Upgrade
PostgreSQL plperlto a version that resolves this vulnerability.Fixed in 17.11 - Upgrade
Upgrade
PostgreSQL plperlto a version that resolves this vulnerability.Fixed in 16.15 - Upgrade
Upgrade
PostgreSQL plperlto a version that resolves this vulnerability.Fixed in 15.19 - Upgrade
Upgrade
PostgreSQL plperlto a version that resolves this vulnerability.Fixed in 14.24
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14670?
The severity of CVE-2026-14670 is rated as high with a score of 8.8.
How does CVE-2026-14670 affect PostgreSQL?
CVE-2026-14670 allows an attacker to execute arbitrary code due to a heap buffer overflow in the plperl tied object.
What versions of PostgreSQL are affected by CVE-2026-14670?
PostgreSQL versions prior to 18.5, 17.11, 16.15, 15.19, and 14.24 are vulnerable to CVE-2026-14670.
How can I mitigate CVE-2026-14670?
To mitigate CVE-2026-14670, upgrade PostgreSQL to a version that is not affected, specifically 18.5 or above.
What type of vulnerability is CVE-2026-14670?
CVE-2026-14670 is categorized as a buffer overflow vulnerability.