What is CVE-2026-14679?
A stack buffer overflow in PostgreSQL argument name matching allows an object creator to write only 0x0 and 0x1 bytes via OUT parameter count. Affected versions include those before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24. Upgrade to the patched versions to mitigate the risk.
Azərbaycanca: PostgreSQL-də arqument adlarının uyğunlaşdırılmasında stack buffer overflow zəifliyi aşkarlanıb. Obyekt yaradıcısı OUT parametr sayı vasitəsilə yalnız 0x0 və 0x1 baytlarını yaza bilər. PostgreSQL 18.5, 17.11, 16.15, 15.19 və 14.24 versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: PostgreSQL
FAQ2
What limited data can an attacker write by exploiting CVE-2026-14679?
An object creator exploiting this stack buffer overflow can only write 0x0 and 0x1 bytes.
To which PostgreSQL versions should I upgrade to fix CVE-2026-14679?
Upgrade to PostgreSQL versions 18.5, 17.11, 16.15, 15.19, and 14.24 to mitigate the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.