CVE-2026-70634: TimescaleDB 2.29.1 Out-of-Bounds Read Information Disclosure via Dictionary Compression Reverse Iterator

Published Aug 6, 2026
·
Updated

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML access to a physical compressed relation can store a crafted datum and run a reverse-order scan. With a pass-by-value column type the out-of-bounds Datum is returned to the client as a normal column value, disclosing backend memory including the shared buffer pool, which SQL access control does not cover.

Affected Software

1 affected component
Timescale TimescaleDB<=2.29.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade TimescaleDB to a version that resolves this vulnerability.

    Patch 517c13e
  2. Compensating control

    Ensure impacted queries do not return out-of-bounds Datum values via pass-by-value column types; prefer pass-by-reference types so disclosed backend memory from the shared buffer pool is not returned as normal column values.

Event History

Aug 6, 2026
CVE Published
via MITRE·04:53 PM
Data Sourced
via MITRE·04:53 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:18 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-70634?

CVE-2026-70634 has a severity score of 8.1, indicating a high risk.

2

What type of vulnerability is CVE-2026-70634?

CVE-2026-70634 is classified as an out-of-bounds read vulnerability.

3

How do I fix CVE-2026-70634?

To fix CVE-2026-70634, upgrade to TimescaleDB version 2.29.2 or later.

4

What can be compromised due to CVE-2026-70634?

CVE-2026-70634 can lead to sensitive information exposure through information disclosure.

5

In which software is CVE-2026-70634 found?

CVE-2026-70634 is found in TimescaleDB version up to 2.29.1.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203