← Vulnerability feed

Vulnerability record · CVE-2026-70635 · published 6 August 2026

CVE-2026-70635: Timescaledb out-of-bounds read vulnerability

Timescale · Timescaledb

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with direct DML access to a non-frozen physical compressed hypertable relation can trigger an out-of-bounds read before the base of the live offsets array through the VectorAgg single-text hashing strategy, resulting in incorrect aggregation output, backend SIGSEGV, or PostgreSQL crash recovery depending on build configuration.

7.1 CVSS 4.0 High EPSS 0.44% · top 63.9% CWE-125 · Out-of-bounds readCWE-129 · CWE-129
7.1CVSS 4.0 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
1 Sep 2026Last modified by NVD

Description

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value, which is stored in the signed int16 Arrow dictionary-index type and bypasses index validation checks in bulk text dictionary decompression. Attackers with direct DML access to a non-frozen physical compressed hypertable relation can trigger an out-of-bounds read before the base of the live offsets array through the VectorAgg single-text hashing strategy, resulting in incorrect aggregation output, backend SIGSEGV, or PostgreSQL crash recovery depending on build configuration.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-70635 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-29089Timescaledb untrusted search path vulnerabilityTimescaleDB is a time-series database for high-performance real-time analytics packaged as a Postgres extension. From version 2.23.0 to 2.25.1, Postg…EPSS 0.19%8.8CVE-2023-25149Timescaledb improper access control vulnerabilityTimescaleDB, an open-source time-series SQL database, has a privilege escalation vulnerability in versions 2.8.0 through 2.9.2. During installation, …EPSS 0.78%8.0CVE-2022-24128Timescaledb incorrect authorization vulnerabilityTimescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands s…EPSS 0.91%7.2CVE-2026-70634Timescaledb out-of-bounds read vulnerabilityTimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compr…EPSS 0.53%7.1CVE-2026-70633Timescaledb out-of-bounds read vulnerabilityTimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator tha…EPSS 0.51%8.8CVE-2026-11645Google Chrome V8 out-of-bounds read and write enables sandbox code executionGoogle Chrome before 149.0.7827.103 contains an out-of-bounds read and write in the V8 JavaScript engine. A crafted HTML page can trigger the memory …KEVEPSS 2.2%analysed7.8CVE-2023-36424Windows Common Log File System Driver out-of-bounds read privilege escalationCVE-2023-36424 is an out-of-bounds read (CWE-125) in the Windows Common Log File System (CLFS) driver that allows elevation of privilege. It affects …KEVEPSS 12%analysed9.3CVE-2026-3055Citrix NetScaler ADC and Gateway SAML IDP memory overreadNetScaler ADC and NetScaler Gateway, when configured as a SAML identity provider, fail to validate input sufficiently, causing an out-of-bounds memor…KEVEPSS 4.0%analysed

Source: NIST National Vulnerability Database (record CVE-2026-70635), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.