๐Ÿ” CVE Alert

CVE-2026-6474

MEDIUM 4.3

PostgreSQL timeofday() can disclose portions of server memory

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CWE CWE-134
Vendor n/a
Product postgresql
Ecosystems
Industries
Technology
Published May 14, 2026
Stay Ahead of the Next One

Get instant alerts for n/a postgresql

Be the first to know when new medium vulnerabilities affecting n/a postgresql are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

n/a / PostgreSQL
18 < 18.4 17 < 17.10 16 < 16.14 15 < 15.18 0 < 14.23

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
postgresql.org: https://www.postgresql.org/support/security/CVE-2026-6474/

Credits

The PostgreSQL project thanks Xint Code for reporting this problem.