There are 2 open security issues in trixie.
1 important issue:
- CVE-2026-103484:
IVFFlat index build in pgvector before 0.8.7 allows a database user to write data out-of-bounds, which can lead to arbitrary code execution.
1 issue left for the package maintainer to handle:
- CVE-2026-3172:
(needs triaging)
Buffer overflow in parallel HNSW index build in pgvector 0.6.0 through 0.8.1 allows a database user to leak sensitive data from other relations or crash the database server.
You can find information about how to handle this issue in the security team's documentation.