Source status: PostgreSQL's CNA records directly thank Ben Morris with Claude and Anthropic Research on three CVEs and David Korczynski with Claude and Ada Logics on CVE-2026-14676. All four carry CVSS 8.8 upstream scores.
Summary
The four accepted reports cover a pg_stat_statements heap overflow, SQL
injection during expression deparsing, an effectively arbitrary-address write
in fuzzystrmatch, and cursor-state type confusion. PostgreSQL’s own records
provide the AI-assisted credits and authoritative severity.
The CVE-2026-14676 credit is shared with other researchers. Bugflation records Claude participation without inferring that TrendAI’s separate reporter credit used an AI system.
References
- PostgreSQL: CVE-2026-14676
- PostgreSQL: CVE-2026-15741
- PostgreSQL: CVE-2026-15742
- PostgreSQL: CVE-2026-16239
- PostgreSQL August 2026 security release
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.