In plain language
What this advisory means
A security flaw was found in pgcollection, an add-on for PostgreSQL databases, that could let someone with access to the database crash it or run harmful code. This happens when the database tries to interpret stored data using the wrong data type. The issue affects versions 2.0.0 through 2.1.1 of pgcollection. Users should upgrade to version 2.1.2 or later to resolve this problem. Amazon's managed PostgreSQL services are not affected, as they use an older version without this issue.
Technical explanation
How the issue affects the environment
CVE-2026-96883 is a type confusion vulnerability in the type coercion logic of the open source pgcollection extension to PostgreSQL. When an authenticated database user requests a stored icollection value as a type incompatible with its actual stored type, pgcollection misinterprets the datum's representation. This improper type casting may allow the user to cause a backend crash or execute arbitrary code within the PostgreSQL server process. Impacted pgcollection versions are 2.0.0 through 2.1.1. The vulnerability has been addressed in pgcollection version 2.1.2. Amazon RDS for PostgreSQL and Amazon Aurora PostgreSQL customers are unaffected as they ship pgcollection version 1.1.1 or older, which does not contain this issue. No workarounds are available.
Operational impact
Why teams should care
This vulnerability allows an authenticated database user to crash the PostgreSQL backend or execute arbitrary code, which could lead to denial of service or unauthorized control of the database server. Organizations using vulnerable pgcollection versions must upgrade to avoid potential operational disruption or compromise. Since Amazon's managed PostgreSQL services are unaffected, only customers who manually deployed the vulnerable versions need action.
Immediate action
To remediate this vulnerability, upgrade any deployment of pgcollection to version 2.1.2 or later. Amazon RDS for PostgreSQL and Amazon Aurora PostgreSQL customers using the managed versions do not require action as they run a safe prior version (1.1.1). After upgrading, verify that the database is functioning correctly and monitor for unusual activity.
Affected and fixed releases
Temporary risk reduction
No workarounds are available for this vulnerability. Mitigation requires upgrading to pgcollection version 2.1.2 or later.
Evidence and validation checklist
- AWS Security Bulletin 2026-118-AWS
- CVE-2026-96883 announcement from AWS Security Bulletins
- Reference to fixed pgcollection version 2.1.2
- Statement that Amazon RDS and Aurora PostgreSQL managed services are unaffected
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
