Type confusion in AWS pgcollection allows remote code execution
High8.8CVE-2026-96883 · Published Sep 24, 2026
Bulletin ID: 2026-118-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 12:00 PM PDT Description: pgcollection is an open source extension to PostgreSQL. We identified CVE-2026-96883, an issue in pgcollection's type coercion logic. When requesting a stored icollection value as a type incompatible with how it was actually stored causes the extension to misinterprets the datum's representation, allowing an authenticated database user to crash the PostgreSQL backend or execute arbitrary code. Impacted versions: pgcollection v2.0.0 through v2.1.1 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. View article
Affected versions
Changes since it was listed
| Date | Change |
|---|---|
| Sep 26 | Severity: Unrated to High |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- NVD
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 25 | REMOVE_BASE_PATH strips every leading repetition of the base path, not just one | Low | 1.1.0 |
| Sep 22 | Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths | High8.8 | No fix yet |
| Sep 22 | Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible... | High8.0 | No fix yet |
| Sep 22 | HTTPS Fallback to HTTP in Graph Explorer | Medium5.9 | No fix yet |
| Sep 22 | Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import | Critical9.0 | No fix yet |
| Sep 22 | Issue with HTTP/2 multi-frame request body inspection in AWS WAF | Critical9.8 | No fix yet |