All findings

CVE-2026-14679 high

PostgreSQL directly credits DepthFirst AI on stack buffer overflow

PostgreSQL directly thanks Zheng Yu of DepthFirst AI for reporting CVE-2026-14679, a high-severity argument-matching stack overflow.

Bug class
Stack buffer overflow with controlled writes to server memory
Affected codebase
PostgreSQL function argument matching
Credited system
DepthFirst
Disclosed
August 13, 2026
Attribution
Direct source attribution
Severity
high
Source status: PostgreSQL's CNA record directly credits Zheng Yu of DepthFirst AI alongside another reporter and assigns CVSS 8.2.

Summary

The argument-matching flaw writes controlled zero and one bytes outside a stack buffer in the PostgreSQL server. This is direct affected-project attribution and is shared with another independent reporter.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.