SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-18022

HIGH · CVSS 8.8 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

An integer wraparound vulnerability in the IVFFlat index build of pgvector versions prior to 0.8.6 allows database users on 32-bit systems to write data out-of-bounds, potentially leading to arbitrary code execution. Organizations using affected versions on 32-bit architectures should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18022
Severity
HIGH
CVSS
8.8
EPSS
0.33%

Original NVD Description

Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.