CVE-2026-18022: pgvector buffer overflow via integer wraparound in IVFFlat index build on 32-bit systems
Published Jul 29, 2026
·Updated
Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.
Affected Software
2 affected components
pgvector pgvector<0.8.6
Pgvector Project Pgvector Postgresql<0.8.6
Remediation
Event History
Jul 29, 2026
CVE Published
via MITRE·06:55 PM
Data Sourced
via MITRE·06:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-18022?
CVE-2026-18022 has a severity rating of high at 8.8.
2
How can CVE-2026-18022 be mitigated?
To mitigate CVE-2026-18022, users should upgrade to pgvector version 0.8.6 or later.
3
Who is affected by CVE-2026-18022?
CVE-2026-18022 affects database users running pgvector on 32-bit systems.
4
What type of vulnerability is CVE-2026-18022?
CVE-2026-18022 is classified as an integer overflow vulnerability.
5
What could be the impact of exploiting CVE-2026-18022?
Exploiting CVE-2026-18022 could allow an attacker to execute arbitrary code due to out-of-bounds memory write.