CVE-2026-3172Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-191CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-02-26); latest day: 1
  • 6 total mentions across 5 days

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-02-25: 1Mentions · 2026-02-26: 2Mentions · 2026-03-04: 1Mentions · 2026-07-21: 1Mentions · 2026-08-22: 1Patch / Workaround · 2026-07-21: 1Patch / Workaround · 2026-08-22: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 202-2502-2603-0407-2108-22
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-251
Disclosure1
2026-02-262
Disclosure2
2026-03-041
General1
2026-07-211
Patch1
2026-08-221
Patch1
Full discourse6 posts
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos PostgreSQL ❗ CVE-2026-3172 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-postgresql/ https://t.co/uvCKKvbm35

    Post summary

    The tweet announces a PostgreSQL vulnerability (CVE‑2026‑3172) and links to a CERT page for further information, but does not provide technical details, exploits, or patch information.

    00001108
    6.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3172 Buffer Overflow in pgvector 0.6.0-0.8.1 Enables Sensitive Data Leakage https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3172

    Post summary

    A buffer overflow vulnerability (CVE-2026-3172) in pgvector versions 0.6.0‑0.8.1 allows sensitive data leakage, with no evidence of exploitation or patch information provided.

    0001041
    4.0K followersView on X
  • Ssanvi Builds@ssanvi_builds
    Patch

    The first stack draft had Seahorse's graph layer on Apache AGE (a Postgres graph extension). The verification pass found plain SQL graph walks are ~290× faster on this workload, with no lock-in to managed Postgres. I dropped AGE. Also pinned pgvector ≥0.8.2 (CVE-2026-3172).

    Post summary

    The author mentions mitigating CVE-2026-3172 by pinning pgvector to version ≥0.8.2 while noting performance gains after dropping Apache AGE, with no evidence of exploits or active attacks.

    0000045
    42 followersView on X
  • Ssanvi Builds@ssanvi_builds
    Patch

    The first stack draft had Seahorse's graph layer on Apache AGE (a Postgres graph extension). The verification pass found plain SQL graph walks are ~290× faster on this workload, with no lock-in to managed Postgres. I dropped AGE. Also pinned pgvector ≥0.8.2 (CVE-2026-3172).

    Post summary

    The message references CVE‑2026‑3172 and a workaround by pinning pgvector to version ≥ 0.8.2, with no exploitation or detailed technical information provided.

    0000036
    40 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3172 Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database se… https://www.cve.org/CVERecord?id=CVE-2026-3172

    Post summary

    CVE‑2026‑3172 is a buffer overflow vulnerability in pgvector’s parallel HNSW index build that can lead to data leakage or database crashes.

    00000136
    56.6K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-3172** pertains to a **buffer overflow** vulnerability within the **parallel HNSW (Hierarchical Navigable Small World)** index build process in **pgvector** versions **0.6.0 through 0.8.1**. This buffer overflow occurs during the construction of the index, which is a critical component for efficient similarity search in vector databases. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #DDoS #BufferOverflow https://cvetodo.com/cve/CVE-2026-3172

    Post summary

    The post announces a buffer overflow vulnerability in pgvector’s parallel HNSW index build process, affecting versions 0.6.0‑0.8.1, with no mention of PoC, exploit, or patch.

    0000041
    20 followersView on X

Explore more