TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-result integrity failures or backend crashes by supplying a crafted Simple8b selector-11 value. This issue can be triggered through the VectorAgg single-text hashing strategy, resulting in incorrect aggregation output, backend SIGSEGV, or PostgreSQL crash rec [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:18:27.857Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path [truncated]
Authenticated attackers with DML access to a compressed hypertable in TimescaleDB can cause a denial of service via an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator. This occurs when a crafted compressed datum with an internally inconsistent BitArray is stored, triggering an unsigned integer wraparound in the reverse iterator bucket index computation. The vulnerability, [truncated]