What is CVE-2026-14678?
This is a buffer over-read vulnerability in the pg_trgm index picksplit function of PostgreSQL. A table maintainer could infer limited memory values through the lossy signal of index split choices. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected; updating is recommended.
Azərbaycanca: Bu, PostgreSQL-in pg_trgm indeksindəki picksplit funksiyasında baş verən buffer over-read zəifliyidir. Təcavüzkar cədvəl saxlayıcısı indeks bölünmə seçimləri vasitəsilə məhdud yaddaş dəyərlərini çıxara bilər. PostgreSQL 18.5, 17.11, 16.15, 15.19 və 14.24 versiyalarından əvvəlki versiyalar təsirlənir; yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
In which component of PostgreSQL is CVE-2026-14678 located?
This vulnerability is located in the picksplit function of the pg_trgm index in PostgreSQL.
Which PostgreSQL versions should be updated to protect against CVE-2026-14678?
Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected, so updating to these versions is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.