Warning: Vulnerability in PostgreSQL Allows Remote Code Execution, Proof-Of-Concept Available, Patch Immediately!
ID: b6c867cb-b45e-53a7-871e-f966a6326098
STIX ID: report--b6c867cb-b45e-53a7-871e-f966a6326098
Threat Score
CVE-2026-14669 is a heap-based buffer overflow in PostgreSQL's to_char() date/time formatting (TZ/TZtz) that allows an authenticated attacker to supply an oversized timezone abbreviation to trigger a heap overflow and potentially achieve arbitrary code execution. PostgreSQL released fixes on 13 August 2026 for supported branches (fixed in 18.5, 17.11, 16.15, 15.19, 14.24); a public proof-of-concept exists and organizations are advised to patch immediately and increase monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
