Source status: PostgreSQL's CNA records directly thank Amy Burnett of OpenAI Codex Security for both reports. Each has a CVSS 8.8 upstream score and fixed-version information.
Summary
CVE-2026-14680 exposes incompatible internal PostgreSQL data structures to
unsafe SQL calls. CVE-2026-16238 conflates range and multirange values in
pg_restore_attribute_stats(). Both can execute code with the database
server’s operating-system privileges.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.