What is CVE-2026-14669?
A critical heap buffer overflow vulnerability in PostgreSQL's `to_char(timestamptz)` function allows a party choosing the timezone to execute arbitrary code as the OS user running the database by supplying a long POSIX timezone abbreviation. All PostgreSQL versions prior to 18.5, 17.11, 16.15, 15.19, and 14.24 are affected, requiring immediate upgrade.
Azərbaycanca: PostgreSQL-in `to_char(timestamptz)` funksiyasında aşkarlanan CVE-2026-14669 kritik heap buffer overflow zəifliyi, təcavüzkara uzun POSIX saat qurşağı abbreviaturası göndərməklə verilənlər bazasını idarə edən OS istifadəçisi kimi ixtiyari kod icra etməyə imkan verir. PostgreSQL-in 18.5, 17.11, 16.15, 15.19 və 14.24 versiyalarından əvvəlki bütün versiyaları təsirlənir, dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: PostgreSQL
FAQ2
Which PostgreSQL versions are affected by CVE-2026-14669?
All PostgreSQL versions prior to 18.5, 17.11, 16.15, 15.19, and 14.24 are affected by this vulnerability.
What can an attacker achieve by exploiting CVE-2026-14669?
An attacker can execute arbitrary code as the OS user running the database by supplying a long POSIX timezone abbreviation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.