Christophe Pettus: The Vector That Lied About Its Dimensions
pgvector 0.8.7 fixes CVE-2026-103484, an out-of-bounds write that can lead to arbitrary code execution when a database user can create an IVFFlat index. Versions through 0.8.6 are affected, making an upgrade relevant to deployments that use those releases.
1 sourcePublished Updated
Why it matters
The flaw can escalate from index creation access to arbitrary code execution in the database backend. Teams running affected pgvector versions should assess exposure and upgrade.