CVE-2026-18022: Pgvector Project Pgvector
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.
Affected products
- Pgvector Project Pgvector: before 0.8.6 (fixed in 0.8.6)
Published 2026-07-29. Last modified 2026-08-20.