VYPR
High severity8.8OSV Advisory· Published Jul 29, 2026· Updated Aug 20, 2026

CVE-2026-18022

CVE-2026-18022

Description

Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Pgvector/PgvectorOSV2 versions
    v0.8.5, v0.8.4, v0.8.3, …+ 1 more
    • (no CPE)range: v0.8.5, v0.8.4, v0.8.3, …
    • (no CPE)range: <0.8.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.