VYPR
High severity8.8NVD Advisory· Published Sep 24, 2026

CVE-2026-96883

CVE-2026-96883

Description

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions.

To remediate this issue, users should upgrade to version 2.1.2 or later.

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.