# pgvector 0.8.7 fixes buffer overflow that can allow arbitrary code execution

_Published Sunday, October 4, 2026 at 9:25 PM EDT · Security · Latest · Tier 2 — Notable_

pgvector 0.8.7 is now available with a fix for a buffer overflow in IVFFlat index builds that can lead to arbitrary code execution, according to its PostgreSQL news announcement. The vulnerability is identified as CVE-2026-103484.

pgvector is an open-source PostgreSQL extension that provides vector similarity search capabilities. The announcement encourages users to upgrade when possible to address the vulnerability in index builds.

## Sources

- [PostgreSQL news](https://www.postgresql.org/about/news/pgvector-087-released-3392/)

---
Canonical: https://techandbusiness.org/newswire/xYrjmW74GOuheMnYx4C4ja
Published: 2026-10-05T01:25:52.416Z
Story chronology: 2026-10-05T00:00:00.000Z
Retrieved: 2026-10-05T03:43:09.000Z
Publisher: Tech & Business (techandbusiness.org)
