2026-118-AWSHigh

CVE-2026-96883 - Type confusion in AWS pgcollection allows remote code execution

Published
September 24, 2026
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Bulletin ID: 2026-118-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 12:00 PM PDT Description: pgcollection is an open source extension to PostgreSQL. We identified CVE-2026-96883, an issue in pgcollection's type coercion logic. When requesting a stored icollection value as a type incompatible with how it was actually stored causes the extension to misinterprets the datum's representation, allowing an authenticated database user to crash the PostgreSQL backend or execute arbitrary code. Impacted versions: pgcollection v2.0.0 through v2.1.1 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. View article

🔗 References (1)