All findings

CVE-2026-14669 high

Codex Security and V12 share credit on PostgreSQL to_char RCE

PostgreSQL directly credits OpenAI Codex Security among the reporters of CVE-2026-14669, while V12 independently maps the accepted heap overflow to its public agentic research.

Bug class
Heap buffer overflow enabling database-server code execution
Affected codebase
PostgreSQL to_char
Credited system
OpenAI Aardvark / Codex Security
Also credited
V12 (self-reported)
Disclosed
August 13, 2026
Attribution
Direct source attribution
Severity
high
Source status: PostgreSQL directly thanks Amy Burnett of OpenAI Codex Security among multiple reporters. V12's public repository supplies its separate agentic attribution. The PostgreSQL CNA assigns CVSS 8.8 and publishes the fixed versions.

Summary

A long POSIX timezone abbreviation could overflow a heap buffer in to_char(timestamptz), allowing code execution as the operating-system user running PostgreSQL. The accepted record has multiple independent reporters.

Bugflation records direct Codex Security attribution and a separate self- reported V12 path while counting CVE-2026-14669 once globally.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.