top of page
perceptive_background_267k.jpg

Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execut…

Published:

28 juli 2026 om 22:00:00

Alert date:

29 juli 2026 om 21:00:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

Database & Storage, Enterprise Applications

CVE-2026-18022 describes an integer wraparound vulnerability in the IVFFlat index build process of pgvector, a PostgreSQL extension for vector similarity search. The flaw affects versions prior to 0.8.6 and is limited to 32-bit systems. A database user can exploit the wraparound condition to write data out-of-bounds in memory. This out-of-bounds write could potentially lead to arbitrary code execution, making it a high-severity issue. The vulnerability was addressed in pgvector version 0.8.6 via a commit to the official GitHub repository. Users running pgvector on 32-bit PostgreSQL deployments are advised to upgrade immediately. The issue was tracked and discussed publicly in the pgvector GitHub issue tracker.

Technical details

Mitigation steps:

Affected products:

pgvector before 0.8.6
PostgreSQL (32-bit systems)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page