CVE-2026-96883

Source
https://cve.org/CVERecord?id=CVE-2026-96883
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-96883.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-96883
Aliases
  • GHSA-g539-cj32-hv6r
Downstream
Published
2026-09-24T19:05:49Z
Modified
2026-09-25T03:48:54Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Type confusion in AWS pgcollection allows remote code execution
Details

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted SQL statements that rely on mismatched type metadata in collection value retrieval and array conversion functions.

To remediate this issue, users should upgrade to version 2.1.2 or later.

Database specific
{
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-843"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96883.json"
}
References

Affected packages

Git / github.com/aws/pgcollection

Affected ranges

Type
GIT
Repo
https://github.com/aws/pgcollection
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.0.0"
        },
        {
            "last_affected": "2.1.1"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v2.*
v2.0.0
v2.1.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-96883.json"