{"id":"CVE-2026-14676","year":2026,"sequence":14676,"component":"contrib module","score":8.8,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","first_published":"2026-08-13","source_url":"https://www.postgresql.org/support/security/CVE-2026-14676/","facts":{"affected":{"18":"18"},"affected_ranges":[{"from":"18","until":"18.6"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-14676","component":"contrib module","cvss_version":"3.0","description_en":"Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.","first_published":"2026-08-13","fixed":{"18":"18.6"},"id":"CVE-2026-14676","introduced":{},"published":{"18":"2026-08-13"},"score":8.8,"title":"PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code","url":"https://www.postgresql.org/support/security/CVE-2026-14676/","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"PostgreSQL pg_stat_statements heap buffer overflow executes arbitrary code","description":"Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.6 are affected. Versions before PostgreSQL 18 are unaffected.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"b6475ce3079fcc0e090f18e7fb1b9ae978acf9f0ba7e41079095c064e82a8e80"},"locales":["en","zh-Hans"],"fixes":[{"major":"18","fixed_version":"18.6","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"18.6","introduced":null,"published":"2026-08-13"}}],"legacy":[{"source":"center","source_id":103,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":103,"cve":"2026-14676","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":"PostgreSQL pg_stat_statements 存在堆缓冲区溢出，查询编写者可通过包含数组常量的特制查询， 以数据库服务所使用的操作系统用户身份执行任意代码。在主版本 18 中，PostgreSQL 18.6 之前的小版本 受此问题影响；PostgreSQL 18 之前的版本不受影响。","component":"contrib module","cvenumber":202614676,"description":"PostgreSQL pg_stat_statements 堆缓冲区溢出可导致任意代码执行","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":429,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":429,"patch_id":103,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}}]},{"source":"pgweb","source_id":103,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":103,"cve":"2026-14676","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":"PostgreSQL pg_stat_statements 存在堆缓冲区溢出，查询编写者可通过包含数组常量的特制查询， 以数据库服务所使用的操作系统用户身份执行任意代码。在主版本 18 中，PostgreSQL 18.6 之前的小版本 受此问题影响；PostgreSQL 18 之前的版本不受影响。","component":"contrib module","cvenumber":202614676,"description":"PostgreSQL pg_stat_statements 堆缓冲区溢出可导致任意代码执行","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":429,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":429,"patch_id":103,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}}]}]}
