Description
IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
Published: 2026-10-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Arbitrary Code Execution
Action: Immediate Patch
AI Analysis

Impact

IVFFlat index build in pgvector versions prior to 0.8.7 contains a buffer overflow that allows a database user to write memory outside the bounds of an internal buffer. The write can corrupt trusted execution context, resulting in arbitrary code execution within the database process. The issue stems from improper bounds checking during the construction of the approximate nearest neighbor index.

Affected Systems

The vulnerability affects the pgvector extension for PostgreSQL. Any installation using pgvector older than version 0.8.7 is vulnerable when creating IVFFlat indices. The specific CNA vendor/product is 'pgvector', and the affected versions are all releases before 0.8.7. The extension must be updated or removed to eliminate the risk.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity with impact on confidentiality, integrity, and availability, classified as arbitrary code execution. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the flaw allows local database users to trigger the overflow. The vulnerability is not listed in the CISA KEV catalog. Attackers can initiate the exploit by executing a CREATE INDEX statement that triggers the IVFFlat build, thereby requiring privileged database user rights or the ability to run arbitrary SQL. The lack of a public exploit reduces risk, but the high CVSS warrants immediate attention.

Generated by OpenCVE AI on October 1, 2026 at 21:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade pgvector to version 0.8.7 or later, which removes the bounds checking flaw.
  • Restrict CREATE INDEX privileges to trusted database roles until the upgrade is complete to prevent untrusted users from building IVFFlat indices.
  • Audit existing indices in the database and rebuild any IVFFlat indices with the updated extension, ensuring the vulnerable build routine is not executed.

Generated by OpenCVE AI on October 1, 2026 at 21:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Pgvector
Pgvector pgvector
Vendors & Products Pgvector
Pgvector pgvector

Thu, 01 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
Title pgvector buffer overflow in IVFFlat index build
Weaknesses CWE-1284
CWE-787
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Pgvector Pgvector
cve-icon MITRE

Status: PUBLISHED

Assigner: PostgreSQL

Published:

Updated: 2026-10-01T19:58:48.937Z

Reserved: 2026-09-30T16:24:57.108Z

Link: CVE-2026-103484

cve-icon Vulnrichment

Updated: 2026-10-01T19:58:39.315Z

cve-icon NVD

Status : Received

Published: 2026-10-01T20:17:23.213

Modified: 2026-10-01T20:17:23.213

Link: CVE-2026-103484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T22:00:17Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-787

    Out-of-bounds Write