PatchSiren cyber security CVE debrief
CVE-2026-6474 Postgresql CVE debrief
CVE-2026-6474 is a PostgreSQL format-string vulnerability in timeofday() that can disclose portions of server memory when crafted timezone zone values are processed. The issue is publicly documented as medium severity and affects PostgreSQL versions before 18.4, 17.10, 16.14, 15.18, and 14.23.
- Vendor
- Postgresql
- Product
- Unknown
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-14
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-14
- Advisory updated
- 2026-05-18
Who should care
PostgreSQL database administrators, application teams that expose or embed PostgreSQL, managed database operators, and security teams responsible for patching database infrastructure should prioritize this issue.
Technical summary
NVD classifies CVE-2026-6474 as an externally controlled format string issue (CWE-134) with network attack vector, low attack complexity, and no privileges or user interaction required in the CVSS record. The vulnerability affects the PostgreSQL timeofday() path and may allow an attacker to retrieve portions of server memory via crafted timezone zone values. The affected release boundaries listed in the record are versions before 18.4, 17.10, 16.14, 15.18, and 14.23.
Defensive priority
Medium. This is a confidentiality-impacting memory disclosure issue rather than an integrity or availability issue, but it should still be patched promptly because the affected code path is reachable and the vulnerability is described as low-complexity.
Recommended defensive actions
- Upgrade PostgreSQL to a fixed release: 18.4, 17.10, 16.14, 15.18, or 14.23, depending on your major version.
- Review any custom extensions, wrappers, or application paths that may exercise timeofday() or timezone-related inputs.
- Validate the installed PostgreSQL major/minor version across all servers, replicas, containers, and managed instances.
- Prioritize Internet-facing or multi-tenant database deployments where a memory disclosure would have higher impact.
- Track the PostgreSQL vendor advisory and NVD entry for any additional remediation guidance or clarifications.
Evidence notes
Based only on the supplied NVD record and the linked PostgreSQL security advisory reference. The record states the vulnerability is an externally controlled format string in timeofday() that can retrieve portions of server memory, maps it to CWE-134, and lists the affected version ceilings. CVSS data in the record is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-6474 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-6474
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-6474 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-6474
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.postgresql.org/support/security/CVE-2026-6474/
f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.