All findings

CVE-2026-14676 + 3 more high

PostgreSQL directly credits Claude-assisted research on four RCE-class CVEs

PostgreSQL's August security release credits Claude and Anthropic Research, or Claude with Ada Logics, across four high-severity server vulnerabilities.

Bug class
Heap overflow, SQL injection, arbitrary-address writes, and type confusion
Affected codebase
PostgreSQL core server and contrib modules
Credited system
Claude / Anthropic Research
Disclosed
August 13, 2026
Attribution
Direct source attribution
Severity
high
Source status: PostgreSQL's CNA records directly thank Ben Morris with Claude and Anthropic Research on three CVEs and David Korczynski with Claude and Ada Logics on CVE-2026-14676. All four carry CVSS 8.8 upstream scores.

Summary

The four accepted reports cover a pg_stat_statements heap overflow, SQL injection during expression deparsing, an effectively arbitrary-address write in fuzzystrmatch, and cursor-state type confusion. PostgreSQL’s own records provide the AI-assisted credits and authoritative severity.

The CVE-2026-14676 credit is shared with other researchers. Bugflation records Claude participation without inferring that TrendAI’s separate reporter credit used an AI system.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.