HIGH 8.7 NVD
CVE-2026-96883
pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user
pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions.
To remediate this issue, users should upgrade to version 2.1.2 or later.
References
- https://aws.amazon.com/security/security-bulletins/2026-118-aws/
- https://github.com/aws/pgcollection/releases/tag/v2.1.2
- https://github.com/aws/pgcollection/security/advisories/GHSA-g539-cj32-hv6r
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-24 via NVD.
vulnfeed aggregates 11711 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.