What is CVE-2026-18022?
This critical vulnerability in pgvector before version 0.8.6 involves an integer wraparound during IVFFlat index build, allowing a database user to write data out-of-bounds. This can enable arbitrary code execution but only affects 32-bit systems. Immediate upgrade to pgvector 0.8.6 or later is strongly recommended.
Azərbaycanca: Bu kritik zəiflik pgvector genişlənməsinin 0.8.6-dan əvvəlki versiyalarında IVFFlat indeks qurulması zamanı baş verən integer wraparound səbəbindən məlumatların buffer hüdudlarından kənara yazılmasına imkan verir. Yalnız 32-bit sistemlər təsirlənir və verilənlər bazası istifadəçisi potensial olaraq ixtiyari kod icra edə bilər. Dərhal pgvector-i ən azı 0.8.6 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
Which versions of pgvector are affected by CVE-2026-18022?
This vulnerability exists in pgvector versions prior to 0.8.6.
Does CVE-2026-18022 affect 64-bit systems?
No, only 32-bit systems are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.