Sceawere

Vulnerability Detail

CVE-2026-103484UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

pgvector IVFFlat Out-of-Bounds Write

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
1d ago
Vendor
n/a
Product
pgvector
Attack Type
Out-of-bounds Write
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-01T20:17:23.213Z",
  "pubdate": "2026-10-01T20:17:23.213Z",
  "executiveSummary": "The pgvector extension for PostgreSQL is susceptible to a critical memory corruption vulnerability during the IVFFlat index construction process.\nThe vulnerability is classified as an out-of-bounds write flaw that occurs prior to version 0.8.7.\nSuccessful exploitation allows an authenticated database user to perform out-of-bounds memory writes, potentially leading to arbitrary code execution within the context of the database process.\nThis vulnerability poses a severe risk to database integrity and system security, as it grants an attacker the ability to bypass memory protections and execute malicious instructions.\nExploitation requires the attacker to have sufficient database privileges to create or manipulate IVFFlat indexes, effectively limiting the attack surface to users with index creation capabilities.\nThe impact includes full compromise of the database server, potential escalation of privileges, and unauthorized data access.",
  "technicalDetails": "The vulnerability originates in the IVFFlat index build mechanism within the pgvector extension. IVFFlat indexes utilize a two-stage approach for approximate nearest neighbor searches, involving clustering vectors into lists and building an inverted file structure.\nThe root cause is an improper bounds check during the memory allocation or data processing phase of index build operations. When processing vectors, the index construction logic fails to sufficiently validate input parameters or index bounds, allowing data to be written into memory regions outside of the intended buffer allocated for the index structure.\nThe attack flow involves an authenticated user crafting specific vector data or manipulating index parameters to trigger the out-of-bounds condition. By sending malformed vector inputs or utilizing index parameters that exceed internal buffer sizes during the index build phase, an attacker can cause the process to overwrite adjacent memory addresses on the heap or stack.\nBecause the PostgreSQL database process operates with specific system-level privileges, corrupting memory at strategic offsets allows the attacker to hijack the control flow of the application. By overwriting function pointers, return addresses, or other critical data structures, the attacker can redirect execution to injected shellcode or perform Return-Oriented Programming (ROP) to bypass Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR).\nThis vulnerability affects all versions of pgvector prior to 0.8.7. It is specifically tied to the internal C-based implementation of the IVFFlat indexing algorithm. Since pgvector is an extension that runs within the PostgreSQL process space, any memory corruption triggered by the extension directly affects the host database process's memory space.\nExploitation does not require external network exposure, as the attack is performed via standard SQL commands used to build or manage indexes. However, it requires the attacker to have permissions to execute index creation commands. Once successful, the arbitrary code execution persists until the database service is restarted or the memory is re-initialized, providing the attacker with significant post-exploitation leverage over the entire database server."
}
CVE-2026-103484: pgvector IVFFlat Out-of-Bounds Write (HIGH Severity, CVSS: 8.8) | Sceawere