What is CVE-2026-14663?
CVE-2026-14663 is a cleartext storage vulnerability in PostgreSQL's pgcrypto extension. It allows a user to recover cleartext from data encrypted with disabled ciphers by directly observing the faulty ciphertext. It is recommended to review pgcrypto configuration and restrict cipher usage.
Azərbaycanca: CVE-2026-14663 PostgreSQL-in pgcrypto uzantısında açıq mətn saxlanması qüsurudur. Bu, sıradan çıxmış şifrləmə alqoritmlərindən istifadə edərək şifrlənmiş məlumatların açıq mətnini əldə etməyə imkan verir. Təhlükəsizlik üçün pgcrypto konfiqurasiyasını nəzərdən keçirmək və şifrləmə alqoritmlərini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: shared vendor: OpenSSL
FAQ2
Which PostgreSQL component does CVE-2026-14663 affect?
This vulnerability affects the pgcrypto extension of PostgreSQL.
What mitigation is recommended for CVE-2026-14663?
It is recommended to review the pgcrypto configuration and restrict cipher usage.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.