Threats Tagged 'cve-2026-14662'
View all threats tagged with 'cve-2026-14662'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-14662'
Click on any threat for detailed analysis and mitigation recommendations
Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an… (CVE-2026-14662)CVE-2026-14662 0 An integer wraparound vulnerability exists in PostgreSQL's tsvector and tsquery data type functions, allowing an unprivileged database user to cause undersized memory allocation and out-of-bounds writes via crafted large inputs. This can lead to arbitrary code execution with the privileges of the operating system user running the database. The vulnerability affects PostgreSQL versions before 18.5, 17.11, 16.15, 15.19, and 14.24. Application users attacking through typical application channels are unlikely to exploit this due to the typical sourcing of these data types from application logic rather than direct user input. Join the discussion | GCVE Database | 08/13/2026, 15:34:34 UTC Added: 08/13/2026, 17:48:23 UTC |
CVE-2026-14662: Integer Overflow or Wraparound in PostgreSQLCVE-2026-14662 0 Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds, via crafted large inputs. This may execute arbitrary code as the operating system user running the database. These types are typically sourced from application logic, not taken from the application's user. Hence, application users attacking the database, through the application as a conduit, are unlikely. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. Join the discussion | CVE Database V5 | 08/13/2026, 13:00:01 UTC Added: 08/13/2026, 13:26:45 UTC |
Showing 1 to 2 of 2 results