Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-14670 is a heap buffer overflow vulnerability in PostgreSQL's PL/Perl extension that allows function owners to execute arbitrary code with database user privileges. The vulnerability exists in how tied hash return values are processed, enabling attackers to craft malicious PL/Perl function bodies that overflow memory buffers and achieve code execution. This affects PostgreSQL versions 14 through 18 before their respective patched releases, impacting any organization running vulnerable PostgreSQL instances with PL/Perl enabled. The attack requires function creation privileges, making it a privilege escalation risk in multi-tenant database environments or scenarios where developers have untrusted access to function creation.
While Casky currently shows zero matching skills for this specific CVE, a Claude AI-powered detection system with extended reasoning would identify the attack patterns by analyzing function creation audit logs, memory access anomalies, and process execution lineage. The underlying attack chain maps to T1190 (Exploit Public-Facing Application) for initial exploitation through crafted PL/Perl code, combined with T1548 (Abuse Elevation Control Mechanism) as the overflow elevates from function owner context to OS-level execution. Extended reasoning would correlate suspicious PL/Perl function definitions containing hash manipulation operations with subsequent unexpected child process spawning or file system modifications under the database user's context. Practitioners would observe findings highlighting function bodies with buffer-overflow patterns, unexpected system calls from database processes, and correlations between function creation timestamps and anomalous OS-level activity.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-14670. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation