{"id":"CVE-2026-14679","year":2026,"sequence":14679,"component":"core server","score":8.2,"cvss_version":"3.0","vector":"AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","first_published":"2026-08-13","source_url":"https://www.postgresql.org/support/security/CVE-2026-14679/","facts":{"affected":{"14":"14","15":"15","16":"16","17":"17","18":"18"},"affected_ranges":[{"from":"0","until":"14.24"},{"from":"15","until":"15.19"},{"from":"16","until":"16.15"},{"from":"17","until":"17.11"},{"from":"18","until":"18.6"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-14679","component":"core server","cvss_version":"3.0","description_en":"Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.","first_published":"2026-08-13","fixed":{"14":"14.24","15":"15.19","16":"16.15","17":"17.11","18":"18.6"},"id":"CVE-2026-14679","introduced":{},"published":{"14":"2026-08-13","15":"2026-08-13","16":"2026-08-13","17":"2026-08-13","18":"2026-08-13"},"score":8.2,"title":"PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory","url":"https://www.postgresql.org/support/security/CVE-2026-14679/","vector":"AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"zh-Hans","title":"PostgreSQL 参数匹配的栈缓冲区溢出可向服务器内存写入 0x0 与 0x1","description":"PostgreSQL 参数匹配的栈缓冲区溢出可向服务器内存写入 0x0 与 0x1","details":"PostgreSQL 参数名匹配存在栈缓冲区溢出，对象创建者可通过 OUT 参数数量造成尚不明确的影响。 该攻击只能写入值为 0x0 和 0x1 的字节。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","format":"markdown","provenance":{"identity":"immutable_cve_code","sources":[{"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"component":"core server","cve":"2026-14679","cvenumber":202614679,"description":"PostgreSQL 参数匹配的栈缓冲区溢出可向服务器内存写入 0x0 与 0x1","details":"PostgreSQL 参数名匹配存在栈缓冲区溢出，对象创建者可通过 OUT 参数数量造成尚不明确的影响。 该攻击只能写入值为 0x0 和 0x1 的字节。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","detailslink":"","id":106,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},"source":"center","source_id":106,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"},{"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"component":"core server","cve":"2026-14679","cvenumber":202614679,"description":"PostgreSQL 参数匹配的栈缓冲区溢出可向服务器内存写入 0x0 与 0x1","details":"PostgreSQL 参数名匹配存在栈缓冲区溢出，对象创建者可通过 OUT 参数数量造成尚不明确的影响。 该攻击只能写入值为 0x0 和 0x1 的字节。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","detailslink":"","id":106,"legacyscore":"","newspost_id":3365,"public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H"},"source":"pgweb","source_id":106,"source_table_sha256":"b57ee28b2263464208af0ccf7512b31f0c1ab7140d12dda09a0c87de341f1372"}]},"text_hash":"d2536e1f0656033cdbdeb421bed17f6da9b56b1abbf13cbe600f08161d6417f0"},"locales":["en","zh-Hans"],"fixes":[{"major":"14","fixed_version":"14.24","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"14.24","introduced":null,"published":"2026-08-13"}},{"major":"15","fixed_version":"15.19","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"15.19","introduced":null,"published":"2026-08-13"}},{"major":"16","fixed_version":"16.15","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"16.15","introduced":null,"published":"2026-08-13"}},{"major":"17","fixed_version":"17.11","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"17.11","introduced":null,"published":"2026-08-13"}},{"major":"18","fixed_version":"18.6","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"18.6","introduced":null,"published":"2026-08-13"}}],"legacy":[{"source":"center","source_id":106,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":106,"cve":"2026-14679","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","details":"PostgreSQL 参数名匹配存在栈缓冲区溢出，对象创建者可通过 OUT 参数数量造成尚不明确的影响。 该攻击只能写入值为 0x0 和 0x1 的字节。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","component":"core server","cvenumber":202614679,"description":"PostgreSQL 参数匹配的栈缓冲区溢出可向服务器内存写入 0x0 与 0x1","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":440,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":440,"patch_id":106,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":441,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":441,"patch_id":106,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":442,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":442,"patch_id":106,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":443,"source_version_id":28,"major":"15","fixed_minor":19,"raw":{"id":443,"patch_id":106,"version_id":28,"fixed_minor":19},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":444,"source_version_id":27,"major":"14","fixed_minor":24,"raw":{"id":444,"patch_id":106,"version_id":27,"fixed_minor":24},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]},{"source":"pgweb","source_id":106,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":106,"cve":"2026-14679","public":true,"vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H","details":"PostgreSQL 参数名匹配存在栈缓冲区溢出，对象创建者可通过 OUT 参数数量造成尚不明确的影响。 该攻击只能写入值为 0x0 和 0x1 的字节。PostgreSQL 18.6、17.11、16.15、15.19 和 14.24 之前的版本受此问题影响。","component":"core server","cvenumber":202614679,"description":"PostgreSQL 参数匹配的栈缓冲区溢出可向服务器内存写入 0x0 与 0x1","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":440,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":440,"patch_id":106,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":441,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":441,"patch_id":106,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}},{"source_id":442,"source_version_id":29,"major":"16","fixed_minor":15,"raw":{"id":442,"patch_id":106,"version_id":29,"fixed_minor":15},"version_raw":{"id":29,"tree":16.0,"current":false,"docsgit":"","eoldate":"2028-11-09","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":15,"firstreldate":"2023-09-14"}},{"source_id":443,"source_version_id":28,"major":"15","fixed_minor":19,"raw":{"id":443,"patch_id":106,"version_id":28,"fixed_minor":19},"version_raw":{"id":28,"tree":15.0,"current":false,"docsgit":"","eoldate":"2027-11-11","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":19,"firstreldate":"2022-10-13"}},{"source_id":444,"source_version_id":27,"major":"14","fixed_minor":24,"raw":{"id":444,"patch_id":106,"version_id":27,"fixed_minor":24},"version_raw":{"id":27,"tree":14.0,"current":false,"docsgit":"","eoldate":"2026-11-12","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":24,"firstreldate":"2021-09-30"}}]}]}
