THREAT OPS › Threat News › [NVD] CVE-2026-14664 (HIGH 8.8) — Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data gro
[NVD] CVE-2026-14664 (HIGH 8.8) — Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data gro
CVE-2026-14664 CVSS: 8.8 HIGH Published: 2026-08-13T13:17:43.847
Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions bef
Indicators of compromise
- CVE-2026-14664cve
- CVE-2026-2006cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14664