


Perceptive Security
SOC/SIEM Consultancy

Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execut…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 21:00:58
Source:
nvd.nist.gov
Database & Storage, Enterprise Applications
CVE-2026-18022 describes an integer wraparound vulnerability in the IVFFlat index build process of pgvector, a PostgreSQL extension for vector similarity search. The flaw affects versions prior to 0.8.6 and is limited to 32-bit systems. A database user can exploit the wraparound condition to write data out-of-bounds in memory. This out-of-bounds write could potentially lead to arbitrary code execution, making it a high-severity issue. The vulnerability was addressed in pgvector version 0.8.6 via a commit to the official GitHub repository. Users running pgvector on 32-bit PostgreSQL deployments are advised to upgrade immediately. The issue was tracked and discussed publicly in the pgvector GitHub issue tracker.
Technical details
Mitigation steps:
Affected products:
pgvector before 0.8.6
PostgreSQL (32-bit systems)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18022
https://github.com/pgvector/pgvector/commit/636a92a3395d2e036ffd40d07aeb400a708ae104
https://github.com/pgvector/pgvector/issues/1006
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
