A high-severity vulnerability, CVE-2026-18022, was disclosed in pgvector affecting version 0.8.5 and earlier. The flaw is an integer wraparound during IVFFlat index building on 32-bit systems that can trigger an out-of-bounds write. According to the disclosure, a database user with the ability to create an IVFFlat index could potentially achieve arbitrary code execution, with the issue mapped to CWE-190 and CWE-787.
The bug was fixed in pgvector 0.8.6, and maintainers advised users running the extension on 32-bit platforms to upgrade. Public reporting credits 0xJi3F with discovering the issue. Severity data published with the CVE lists a CVSS v3.1 vector of AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, while the accompanying assessment said there was no known exploitation at the time of disclosure.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A new CVE entry was published for an integer wraparound vulnerability in pgvector before version 0.8.6 affecting IVFFlat index building on 32-bit systems. The entry describes potential out-of-bounds writes and possible arbitrary code execution, with no known exploitation noted.
The disclosure states that CVE-2026-18022 affects pgvector 0.8.5 and earlier and was fixed in version 0.8.6. Users on 32-bit systems were advised to upgrade.
The vulnerability disclosure for CVE-2026-18022 credits 0xJi3F with discovering an integer wraparound flaw in pgvector's IVFFlat index build on 32-bit systems that can lead to out-of-bounds writes and possible arbitrary code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.