CVE-2026-103484
IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
- CVSS
- 8.8
- EPSS
- 0.004 (34.3th percentile)
- CISA KEV
- Not listed
- Exploitation
- none
- Public exploits
- None seen
- State
- PUBLISHED
Coverage
Planet PostgreSQLSpecialist. Specialist publisher: established trade press, or expert analysis with a track record
Christophe Pettus: The Vector That Lied About Its Dimensions
pgvector 0.8.7 fixes CVE-2026-103484: a database user who can create an IVFFlat index can write out of bounds in the backend, which can lead to arbitrary code execution. Every version through 0.8.6 is affected. Upgrade. That part is simple. Two other parts are not: who can actually reach the bug,……
What we observed
No signals recorded