CVE-2026-18022: Pgvector Project Pgvector

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary code execution. Only 32-bit systems are affected.

Affected products

Published 2026-07-29. Last modified 2026-08-20.