Security Advisory Desk
unratedQCS priority 76/100Amazon Web Services

CVE-2026-96883 - Type confusion in AWS pgcollection allows remote code execution

A security flaw was found in pgcollection, an add-on for PostgreSQL databases, that could let someone with access to the database crash it or run harmful code. This happens when the database tries to interpret stored data using the wrong data type. The issue affects versions 2.0.0 through 2.1.1 of pgcollection. Users should upgrade to version 2.1.2 or later to resolve this problem. Amazon's managed PostgreSQL services are not affected, as they use an older version without this issue.

QCS published 5/10/2026, 6:03:29 am ISTVendor disclosure 25/9/2026, 12:47:16 am ISTVerified 5/10/2026, 6:03:29 am ISTRevision 1

In plain language

What this advisory means

A security flaw was found in pgcollection, an add-on for PostgreSQL databases, that could let someone with access to the database crash it or run harmful code. This happens when the database tries to interpret stored data using the wrong data type. The issue affects versions 2.0.0 through 2.1.1 of pgcollection. Users should upgrade to version 2.1.2 or later to resolve this problem. Amazon's managed PostgreSQL services are not affected, as they use an older version without this issue.

Technical explanation

How the issue affects the environment

CVE-2026-96883 is a type confusion vulnerability in the type coercion logic of the open source pgcollection extension to PostgreSQL. When an authenticated database user requests a stored icollection value as a type incompatible with its actual stored type, pgcollection misinterprets the datum's representation. This improper type casting may allow the user to cause a backend crash or execute arbitrary code within the PostgreSQL server process. Impacted pgcollection versions are 2.0.0 through 2.1.1. The vulnerability has been addressed in pgcollection version 2.1.2. Amazon RDS for PostgreSQL and Amazon Aurora PostgreSQL customers are unaffected as they ship pgcollection version 1.1.1 or older, which does not contain this issue. No workarounds are available.

Operational impact

Why teams should care

This vulnerability allows an authenticated database user to crash the PostgreSQL backend or execute arbitrary code, which could lead to denial of service or unauthorized control of the database server. Organizations using vulnerable pgcollection versions must upgrade to avoid potential operational disruption or compromise. Since Amazon's managed PostgreSQL services are unaffected, only customers who manually deployed the vulnerable versions need action.

Immediate action

To remediate this vulnerability, upgrade any deployment of pgcollection to version 2.1.2 or later. Amazon RDS for PostgreSQL and Amazon Aurora PostgreSQL customers using the managed versions do not require action as they run a safe prior version (1.1.1). After upgrading, verify that the database is functioning correctly and monitor for unusual activity.

Affected and fixed releases

Affected versionspgcollection v2.0.0, pgcollection v2.1.1
Fixed versionspgcollection v2.1.2

Temporary risk reduction

No workarounds are available for this vulnerability. Mitigation requires upgrading to pgcollection version 2.1.2 or later.

Evidence and validation checklist

  • AWS Security Bulletin 2026-118-AWS
  • CVE-2026-96883 announcement from AWS Security Bulletins
  • Reference to fixed pgcollection version 2.1.2
  • Statement that Amazon RDS and Aurora PostgreSQL managed services are unaffected

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source