VYPR
Unrated severityOSV Advisory· Published Jul 30, 2026

Debian pgvector: Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a data…

CVE-2026-18022

Description

Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.

Affected products

2
  • Pgvector/PgvectorOSV2 versions
    v0.8.5, v0.8.4, v0.8.3, …+ 1 more
    • (no CPE)range: v0.8.5, v0.8.4, v0.8.3, …
    • (no CPE)range: <0.8.6

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.