Skip to content

CVE-2026-96883

Aws.Amazon • September 24, 2026

Bulletin ID: 2026-118-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 12:00 PM PDT

pgcollection is an open source extension to PostgreSQL. We identified CVE-2026-96883 , an issue in pgcollection's type coercion logic. When requesting a stored icollection value as a type incompatible with how it was actually stored causes the extension to misinterprets the datum's representation, allowing an authenticated database user to crash the PostgreSQL backend or execute arbitrary code.

Impacted versions: pgcollection v2.0.0 through v2.1.1

This issue has been addressed in pgcollection version 2.1.2 . This issue does not impact existing Amazon RDS for PostgreSQL and Amazon Aurora PostgreSQL customers. These services only ship 1.1.1 version, which does not contain this issue.

Customers who downloaded and compiled pgcollection 2.0.0 through 2.1.1 from the AWS GitHub repository and deployed them in their own PostgreSQL environments should upgrade to version 2.1.2 or later.

Please email [email protected] with any security questions or concerns.

Extracted Entities

Companies (2)

Email Addresses (1)

Platforms (1)