High severity8.8OSV Advisory· Published Jul 29, 2026· Updated Aug 20, 2026
CVE-2026-18022
CVE-2026-18022
Description
Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/pgvector/pgvector/commit/636a92a3395d2e036ffd40d07aeb400a708ae104nvdPatch
- github.com/pgvector/pgvector/issues/1006nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.