AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14679

HIGH · CVSS 8.2 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

A stack buffer overflow vulnerability in PostgreSQL's argument name matching can be exploited by an object creator to manipulate OUT parameter counts, potentially leading to undefined behavior. This flaw allows for the writing of limited byte values (0x0 and 0x1), which could compromise system integrity. Organizations using affected PostgreSQL versions prior to 18.5, 17.11, 16.15, 15.19, and 14.24 should prioritize patching to mitigate the risk.

CVE
CVE-2026-14679
Severity
HIGH
CVSS
8.2
EPSS
0.40%

Original NVD Description

Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.