Christophe Pettus: The Vector That Lied About Its Dimensions

pgvector 0.8.7 fixes CVE-2026-103484: a database user who can create an IVFFlat index can write out of bounds in the backend, which can lead to arbitrary code execution. Every version through 0.8.6 is affected. Upgrade. That part is simple. Two other parts are not: who can actually reach the bug,……

cloudsecurity

Sources

Vulnerabilities

Why this score
Signals contributing to the severity score
SignalPoints
cvss high — 8.810