CVE-2026-14669
Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the party choosing the timezone to execute arbitrary code as the operating system user running the database, via a long POSIX timezone abbreviation. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
- Affected products
- Postgresql
- Postgresql
- < 14.24, 15.19, 16.15, 17.11, 18.5
- CVSS 3.1
- 8.8 HIGH
- EPSS
- 0.6% (47th percentile)
- Weakness
- CWE-122
- NVD status
- Analyzed
- Published
- 2026-08-13
CVE-2026-14669 at NVD
1 known exploit for CVE-2026-14669
Proof-of-concept code and exploit modules indexed by Sploitus