Stories

  1. Christophe Pettus: The Vector That Lied About Its Dimensions

    pgvector 0.8.7 fixes CVE-2026-103484, an out-of-bounds write that can lead to arbitrary code execution when a database user can create an IVFFlat index. Versions through 0.8.6 are affected, making an upgrade relevant to deployments that use those releases.

  2. pgvector 0.8.7 Released

    pgvector 0.8.7 fixes a buffer overflow in IVFFlat index builds that can lead to arbitrary code execution. The release identifies the issue as CVE-2026-103484 and urges users to upgrade.

Topics

Publishers