PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-6474 Postgresql CVE debrief

CVE-2026-6474 is a PostgreSQL format-string vulnerability in timeofday() that can disclose portions of server memory when crafted timezone zone values are processed. The issue is publicly documented as medium severity and affects PostgreSQL versions before 18.4, 17.10, 16.14, 15.18, and 14.23.

Vendor
Postgresql
Product
Unknown
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-14
Original CVE updated
2026-05-18
Advisory published
2026-05-14
Advisory updated
2026-05-18

Who should care

PostgreSQL database administrators, application teams that expose or embed PostgreSQL, managed database operators, and security teams responsible for patching database infrastructure should prioritize this issue.

Technical summary

NVD classifies CVE-2026-6474 as an externally controlled format string issue (CWE-134) with network attack vector, low attack complexity, and no privileges or user interaction required in the CVSS record. The vulnerability affects the PostgreSQL timeofday() path and may allow an attacker to retrieve portions of server memory via crafted timezone zone values. The affected release boundaries listed in the record are versions before 18.4, 17.10, 16.14, 15.18, and 14.23.

Defensive priority

Medium. This is a confidentiality-impacting memory disclosure issue rather than an integrity or availability issue, but it should still be patched promptly because the affected code path is reachable and the vulnerability is described as low-complexity.

Recommended defensive actions

  • Upgrade PostgreSQL to a fixed release: 18.4, 17.10, 16.14, 15.18, or 14.23, depending on your major version.
  • Review any custom extensions, wrappers, or application paths that may exercise timeofday() or timezone-related inputs.
  • Validate the installed PostgreSQL major/minor version across all servers, replicas, containers, and managed instances.
  • Prioritize Internet-facing or multi-tenant database deployments where a memory disclosure would have higher impact.
  • Track the PostgreSQL vendor advisory and NVD entry for any additional remediation guidance or clarifications.

Evidence notes

Based only on the supplied NVD record and the linked PostgreSQL security advisory reference. The record states the vulnerability is an externally controlled format string in timeofday() that can retrieve portions of server memory, maps it to CWE-134, and lists the affected version ceilings. CVSS data in the record is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-6474 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-6474

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-6474 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6474

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://www.postgresql.org/support/security/CVE-2026-6474/

    f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 - Patch, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.