← Founder Notes
Archive

The vector store just shipped a security patch. pgvector 0.8.7, out oct 8, closes a buffer overflow…

Yethikrishna ROriginal on Threads

the vector store just shipped a security patch. pgvector 0.8.7, out oct 8, closes a buffer overflow in ivfflat index creation that could run arbitrary code.

the nearest neighbor lookup now needs a cve watch.

Context

Verified dates: the pgvector 0.8.7 changelog is dated Oct 1, 2026 and lists a fix for a buffer overflow with IVFFlat index build. The PostgreSQL news item announcing the release is dated Oct 5, 2026 and says the flaw is CVE-2026-103484, which can lead to arbitrary code execution. The GitHub Advisory Database published it on Oct 1, 2026 with High severity.

The CVE record says an IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds (CWE-787). Red Hat adds that an authenticated user could instead cause a crash and denial of service.

How it compares

The buffer overflow in IVFFlat index creation, arbitrary code execution and the 0.8.7 patch match. The release date is Oct 1, not Oct 8; Oct 5 is the PostgreSQL announcement date. The flaw needs an authenticated database user, which the Red Hat entry states. 'The nearest neighbor lookup now needs a CVE watch' is the author's opinion.

Related work

Watch next

  • Check whether managed Postgres providers have shipped 0.8.7.

Sources

  1. PostgreSQL news: pgvector 0.8.7 releasedpostgresql.org
  2. PGXN: pgvector 0.8.7 changelogpgxn.org
  3. CVE Record: CVE-2026-103484cve.org

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 11 October 2026 at 18:17 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/the-vector-store-just-shipped-a-security-patch-DeWsXqtjBQe" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="The vector store just shipped a security patch. pgvector 0.8.7, out oct 8, closes a buffer overflow…"></iframe>

More notes