Source status: PostgreSQL directly thanks Amy Burnett of OpenAI Codex Security among multiple reporters. V12's public repository supplies its separate agentic attribution. The PostgreSQL CNA assigns CVSS 8.8 and publishes the fixed versions.
Summary
A long POSIX timezone abbreviation could overflow a heap buffer in
to_char(timestamptz), allowing code execution as the operating-system user
running PostgreSQL. The accepted record has multiple independent reporters.
Bugflation records direct Codex Security attribution and a separate self- reported V12 path while counting CVE-2026-14669 once globally.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.