AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14678

MEDIUM · CVSS 4.3 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A buffer over-read vulnerability in the pg_trgm index picksplit function of PostgreSQL could allow a table maintainer to infer sensitive memory values by reading past the end of a heap buffer. This issue affects versions prior to PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24, and should be prioritized by database administrators and organizations using these affected versions to mitigate potential data leakage risks.

CVE
CVE-2026-14678
Severity
MEDIUM
CVSS
4.3
EPSS
0.29%

Original NVD Description

Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffer. This might allow a table maintainer to infer limited memory values, via the lossy signal of index split choices. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.