PostgreSQL ctid estimator type confusion allows memory leakage (before 18.5)
CVE-2026-14668 Published on August 13, 2026

PostgreSQL ctid type confusion in selectivity estimator discloses derivative of arbitrary read
Type confusion regarding input of PostgreSQL ctid data type selectivity estimator allows an object creator to view a calculation derived from the value of an arbitrary 4-byte span of memory, via a chosen non-ctid input. While the calculation loses precision, substantial memory value recovery appears possible. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

NVD

Weakness Type

What is an Object Type Confusion Vulnerability?

The program allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

CVE-2026-14668 has been classified to as an Object Type Confusion vulnerability or weakness.


Products Associated with CVE-2026-14668

Want to know whenever a new CVE is published for PostgreSQL? stack.watch will email you.