Format String Vulnerability in PostgreSQL Affects Memory Integrity
CVE-2026-6474
4.3MEDIUM
What is CVE-2026-6474?
A format string vulnerability exists in the PostgreSQL timeofday() function, allowing attackers to manipulate crafted timezone inputs to access sensitive portions of server memory. This issue affects multiple versions of PostgreSQL and poses a significant risk if exploited, as it can lead to unauthorized data exposure.
Affected Version(s)
PostgreSQL 18 < 18.4
PostgreSQL 17 < 17.10
PostgreSQL 16 < 16.14
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The PostgreSQL project thanks Xint Code for reporting this problem.