Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-14676

CVE-2026-14676: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh8.8

    High [CVE-2026-14676] PostgreSQL pg_stat_statements: Arbitrary code execution via heap buffer overflow

    CVE-2026-14676Source published Source updated

    Heap buffer overflow in PostgreSQL pg_stat_statements allows the query author to execute arbitrary code as the operating system user running the database, via crafted queries containing array constants. Within major version 18, minor versions before PostgreSQL 18.5 are affected. The pg_stat_statements extension must be loaded (via shared_preload_libraries) for the vulnerability to be exploitable. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:67280, RHSA-2026:67848. Affected products named by the advisory: Red Hat package: postgresql18.

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 9
    • Red Hat package: postgresql18
    Source-reported affected versions
    • < 18.5
    Source-reported fixed versions
    • postgresql18-0:18.6-1.el10_2
    • postgresql:18-9080020260914093252.rhel9
    • RHSA-2026:67280
    • RHSA-2026:67848
    Mitigation guidance
    • If upgrading to PostgreSQL 18.5 or later is not immediately possible, the pg_stat_statements extension can be disabled as a workaround. Remove 'pg_stat_statements' from the shared_preload_libraries parameter in postgresql.conf and restart the PostgreSQL service. This disables query statistics tracking but fully eliminates the attack surface for this vulnerability, as the heap buffer overflow exists exclusively within the pg_stat_statements query-normalization code path and is not reachable when the extension is not loaded. Additionally, limiting database access to trusted, vetted users reduces exposure, though it does not eliminate the risk for any authenticated user who can submit arbitrary queries.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery