Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.postgresql.org/support/security/CVE-2026-14679/ |
|
History
Thu, 13 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Postgresql
Postgresql postgresql |
|
| Vendors & Products |
Postgresql
Postgresql postgresql |
Thu, 13 Aug 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected. | |
| Title | PostgreSQL stack buffer overflow in argument match writes 0x0 and 0x1 to server memory | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-08-13T15:37:06.930Z
Reserved: 2026-07-03T20:28:17.880Z
Link: CVE-2026-14679
Updated: 2026-08-13T15:37:02.416Z
Status : Received
Published: 2026-08-13T13:17:45.277
Modified: 2026-08-13T16:17:57.033
Link: CVE-2026-14679
No data.
OpenCVE Enrichment
Updated: 2026-08-13T14:45:03Z