{"id":"CVE-2026-14662","year":2026,"sequence":14662,"component":"core server","score":8.8,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","first_published":"2026-08-13","source_url":"https://www.postgresql.org/support/security/CVE-2026-14662/","facts":{"affected":{"14":"14","15":"15","16":"16","17":"17","18":"18"},"affected_ranges":[{"from":"0","until":"14.24"},{"from":"15","until":"15.19"},{"from":"16","until":"16.15"},{"from":"17","until":"17.11"},{"from":"18","until":"18.6"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-14662","component":"core server","cvss_version":"3.0","description_en":"Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.","first_published":"2026-08-13","fixed":{"14":"14.24","15":"15.19","16":"16.15","17":"17.11","18":"18.6"},"id":"CVE-2026-14662","introduced":{},"published":{"14":"2026-08-13","15":"2026-08-13","16":"2026-08-13","17":"2026-08-13","18":"2026-08-13"},"score":8.8,"title":"PostgreSQL tsvector and tsquery undersize allocations, via integer wraparound","url":"https://www.postgresql.org/support/security/CVE-2026-14662/","vector":"AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL tsvector 与 tsquery 因整数回绕而分配过小的内存","description":"PostgreSQL tsvector 与 tsquery 因整数回绕而分配过小的内存","details":"PostgreSQL 的 tsvector 与 tsquery 数据类型函数存在整数回绕，无特权数据库用户可通过特制的大型输入， 使服务器分配过小的内存并越界写入，进而可能以数据库服务所使用的操作系统用户身份执行任意代码。 这些类型通常由应用逻辑生成，而不是直接取自应用用户，因此应用用户借助应用作为通道攻击数据库的可能性较低。 CVE-2026-6473 修复过类似问题。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2026-14662","cvenumber":202614662,"description":"PostgreSQL tsvector 与 tsquery 因整数回绕而分配过小的内存","details":"PostgreSQL 的 tsvector 与 tsquery 数据类型函数存在整数回绕，无特权数据库用户可通过特制的大型输入， 使服务器分配过小的内存并越界写入，进而可能以数据库服务所使用的操作系统用户身份执行任意代码。 这些类型通常由应用逻辑生成，而不是直接取自应用用户，因此应用用户借助应用作为通道攻击数据库的可能性较低。 CVE-2026-6473 修复过类似问题。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","detailslink":"","id":102,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"source":"center","source_id":102,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2026-14662","cvenumber":202614662,"description":"PostgreSQL tsvector 与 tsquery 因整数回绕而分配过小的内存","details":"PostgreSQL 的 tsvector 与 tsquery 数据类型函数存在整数回绕，无特权数据库用户可通过特制的大型输入， 使服务器分配过小的内存并越界写入，进而可能以数据库服务所使用的操作系统用户身份执行任意代码。 这些类型通常由应用逻辑生成，而不是直接取自应用用户，因此应用用户借助应用作为通道攻击数据库的可能性较低。 CVE-2026-6473 修复过类似问题。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","detailslink":"","id":102,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"source":"pgweb","source_id":102,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"ec6cb0d173436dedc1aafc06b23581fa9e559ec0b320c51bdbb702d041663d66"},"locales":["en","zh-Hans"],"fixes":[{"major":"14","fixed_version":"14.24","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"14.24","introduced":null,"published":"2026-08-13"}},{"major":"15","fixed_version":"15.19","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"15.19","introduced":null,"published":"2026-08-13"}},{"major":"16","fixed_version":"16.15","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"16.15","introduced":null,"published":"2026-08-13"}},{"major":"17","fixed_version":"17.11","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"17.11","introduced":null,"published":"2026-08-13"}},{"major":"18","fixed_version":"18.6","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"18.6","introduced":null,"published":"2026-08-13"}}],"legacy":[{"source":"center","source_id":102,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":102,"cve":"2026-14662","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":"PostgreSQL 的 tsvector 与 tsquery 数据类型函数存在整数回绕，无特权数据库用户可通过特制的大型输入， 使服务器分配过小的内存并越界写入，进而可能以数据库服务所使用的操作系统用户身份执行任意代码。 这些类型通常由应用逻辑生成，而不是直接取自应用用户，因此应用用户借助应用作为通道攻击数据库的可能性较低。 CVE-2026-6473 修复过类似问题。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","component":"core server","cvenumber":202614662,"description":"PostgreSQL tsvector 与 tsquery 因整数回绕而分配过小的内存","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":424,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":424,"patch_id":102,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":425,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":425,"patch_id":102,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":426,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":426,"patch_id":102,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":427,"source_version_id":28,"major":"15","fixed_minor":19,"raw":{"id":427,"patch_id":102,"version_id":28,"fixed_minor":19},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":428,"source_version_id":27,"major":"14","fixed_minor":24,"raw":{"id":428,"patch_id":102,"version_id":27,"fixed_minor":24},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":102,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":102,"cve":"2026-14662","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","details":"PostgreSQL 的 tsvector 与 tsquery 数据类型函数存在整数回绕，无特权数据库用户可通过特制的大型输入， 使服务器分配过小的内存并越界写入，进而可能以数据库服务所使用的操作系统用户身份执行任意代码。 这些类型通常由应用逻辑生成，而不是直接取自应用用户，因此应用用户借助应用作为通道攻击数据库的可能性较低。 CVE-2026-6473 修复过类似问题。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","component":"core server","cvenumber":202614662,"description":"PostgreSQL tsvector 与 tsquery 因整数回绕而分配过小的内存","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":424,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":424,"patch_id":102,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":425,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":425,"patch_id":102,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":426,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":426,"patch_id":102,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":427,"source_version_id":28,"major":"15","fixed_minor":19,"raw":{"id":427,"patch_id":102,"version_id":28,"fixed_minor":19},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":428,"source_version_id":27,"major":"14","fixed_minor":24,"raw":{"id":428,"patch_id":102,"version_id":27,"fixed_minor":24},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
