What is CVE-2026-14664?
This is a heap buffer overflow vulnerability in PostgreSQL's regexp engine, allowing the query author to execute arbitrary code as the operating system user running the database via text that would not pass encoding validation (shares heritage with CVE-2026-2006).
Azərbaycanca: Bu, PostgreSQL-in regexp funksiyasında "heap buffer overflow" zəifliyidir. Kodlaşdırma validasiyasından keçməyən mətn vasitəsilə sorğu müəllifinə verilənlər bazasını işlədən sistem istifadəçisi adından ixtiyari kod icra etməyə imkan verir (CVE-2026-2006 ilə oxşarlıq daşıyır).
Related CVEs
link basis: same weakness class CWE-119; shared vendor: PostgreSQL
FAQ2
What is CVE-2026-14664?
This is a heap buffer overflow vulnerability in PostgreSQL's regexp engine, allowing the query author to execute arbitrary code as the operating system user running the database via text that would not pass encoding validation.
Which other vulnerability shares heritage with CVE-2026-14664?
This vulnerability shares heritage with CVE-2026-2006, meaning it has a similar root cause or impact mechanism.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.