securityonline.info 8/24/2026, 2:31:53 PM · external

PostgreSQL Issues Fix for Critical CVE-2026-14669 Remote Code Bug

PostgreSQL Issues Fix for Critical CVE-2026-14669 Remote Code Bug
CyberSIXT Evidence Panel
Primary Source postgresql.org
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

POSTGRESQL has addressed a critical heap buffer overflow vulnerability classified as CVE-2026-14669, which can lead to remote code execution and has a CVSS score of 8.8. The flaw exists in the to_char() function related to timestamp formatting, where insufficient length checks allow for buffer overflows. The vulnerability affects PostgreSQL versions earlier than 18.5, 17.11, 16.15, 15.19, and 14.24. Users are advised to update to the patched versions to mitigate risks, as proof-of-concept exploit code is publicly available.

View Primary Source Via securityonline.info

Article by CyberSIXT