What is CVE-2026-14670?
A heap buffer overflow vulnerability in the PostgreSQL plperl extension when returning a tied hash allows the function owner to execute arbitrary code as the database's OS user. Affected versions prior to PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 require immediate patching.
Azərbaycanca: PostgreSQL-in plperl genişləndirilməsində `tied hash` qaytarılması zamanı heap buffer overflow zəifliyi aşkarlanıb. Bu, funksiya sahibinə verilənlər bazasını işlədən OS istifadəçisi olaraq ixtiyari kod icra etməyə imkan verir. PostgreSQL 18.5, 17.11, 16.15, 15.19, 14.24 və daha köhnə versiyalar təsirlənir, dərhal yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which PostgreSQL component was CVE-2026-14670 discovered?
The vulnerability was discovered in the PostgreSQL plperl extension, caused by a heap buffer overflow when returning a tied hash.
What can an attacker gain by exploiting this vulnerability?
The function owner can execute arbitrary code as the operating system user running the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.