CVE-2026-96883
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions.
To remediate this issue, users should upgrade to version 2.1.2 or later.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| AWS | pgcollection | 2.0.0 <= 2.1.1 | affected |
Weaknesses
- CWE-843: CWE-843 Access of resource using incompatible type ('type confusion')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/aws/pgcollection/releases/tag/v2.1.2
- https://aws.amazon.com/security/security-bulletins/2026-118-aws/
- https://github.com/aws/pgcollection/security/advisories/GHSA-g539-cj32-hv6r
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.