Heap buffer overflow in PostgreSQL regexp allows the query author to execute arbitrary code as the operating system user running the database, via text that would not pass encoding validation. This shares heritage with CVE-2026-2006, but this case involved unanticipated data growth when round-tripped through pg_wchar. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-14664 is a heap buffer overflow vulnerability in PostgreSQL's regular expression handling that occurs during character encoding round-tripping through pg_wchar. When specially crafted text that bypasses encoding validation is processed, it can cause unexpected data growth, leading to out-of-bounds memory writes. This allows an authenticated query author to execute arbitrary code with the privileges of the database system user—a critical impact for any organization relying on PostgreSQL. Affected versions span PostgreSQL 14 through 18, making this a widespread threat across legacy and modern deployments.
While this CVE currently has zero mapped MITRE ATT&CK techniques, Casky's Claude-powered analysis would identify the underlying attack patterns as potential **Execution** and **Privilege Escalation** techniques. A practitioner using Casky would observe findings related to CWE-122 (heap-based buffer overflow) detection in database query logs, unexpected process behavior from the postgres daemon, and anomalous memory access patterns. The platform's extended reasoning capability would flag the connection between encoding validation bypasses and code execution risk, helping security teams prioritize patching efforts and investigate whether database queries contain suspicious regexp patterns or text that could trigger the overflow condition. The absence of active exploitation (per CISA KEV) provides a critical window for remediation before threat actors weaponize this vulnerability.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-14664. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation