POSTGRESQL has addressed a critical heap buffer overflow vulnerability classified as CVE-2026-14669, which can lead to remote code execution and has a CVSS score of 8.8. The flaw exists in the to_char() function related to timestamp formatting, where insufficient length checks allow for buffer overflows. The vulnerability affects PostgreSQL versions earlier than 18.5, 17.11, 16.15, 15.19, and 14.24. Users are advised to update to the patched versions to mitigate risks, as proof-of-concept exploit code is publicly available.
PostgreSQL Issues Fix for Critical CVE-2026-14669 Remote Code Bug
CyberSIXT Evidence Panel
Article by CyberSIXT