All findings

CVE-2026-14680, CVE-2026-16238 high

PostgreSQL directly credits Codex Security on two type-confusion RCEs

PostgreSQL's August security release directly credits OpenAI Codex Security on two high-severity type-confusion vulnerabilities.

Bug class
Type confusion enabling arbitrary code execution as the database operating-system user
Affected codebase
PostgreSQL core server
Credited system
OpenAI Aardvark / Codex Security
Disclosed
August 13, 2026
Attribution
Direct source attribution
Severity
high
Source status: PostgreSQL's CNA records directly thank Amy Burnett of OpenAI Codex Security for both reports. Each has a CVSS 8.8 upstream score and fixed-version information.

Summary

CVE-2026-14680 exposes incompatible internal PostgreSQL data structures to unsafe SQL calls. CVE-2026-16238 conflates range and multirange values in pg_restore_attribute_stats(). Both can execute code with the database server’s operating-system privileges.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.