CVE-2026-70635Patch(timescale / timescaledb)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch timescale timescaledb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with direct DML access to a non-frozen physical compressed hypertable relation can trigger an out-of-bounds read before the base of the live offsets array through the VectorAgg single-text hashing strategy, resulting in incorrect aggregation output, backend SIGSEGV, or PostgreSQL crash recovery depending on build configuration.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-129

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • timescaledb

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
timescaledb

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-07: 1Patch / Workaround · 2026-08-07: 108-07
Signal classification1 categories
Patch
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • MalwareObserver@MalwareObserver
    Patch

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-70635](https://github.com/timescale/timescaledb/commit/517c13e7cc6afadb4a7deaa7a5a5a290... https://github.com/timescale/timescaledb/commit/517c13e7cc6afadb4a7deaa7a5a5a29065e5b5a3 #PatchManagement #Vulnerability #CVE

    Post summary

    The tweet announces CVE‑2026‑70635 and links to a GitHub commit that presumably contains a patch, without providing details on exploitation or vulnerability specifics.

    0000041
    18 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptimescaletimescaledb---

Explore more