Skip to main content
EPSS 0.5%top 62%

CVE-2026-6477: Use of Inherently Dangerous Function in PostgreSQL

0
High
Published: 05/14/2026 (05/14/2026, 13:00:12 UTC)
Source: CVE Database V5
Product: PostgreSQL

Description

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS v3.1

Score 8.8high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected software

PostgreSQL

Affected versions
>=18 <18.4>=17 <17.10>=16 <16.14>=15 <15.18>=0 <14.23
Postgresqlmore threats →ai
postgresql/postgresql
pkg:deb/postgresql/postgresql
Affected versions
<14.23<15.18<16.14<17.10<18.4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 14:24:16 UTC

Technical Analysis

This vulnerability arises from the use of an inherently unsafe function PQfn in PostgreSQL's libpq client library, which does not properly limit the size of data copied into client stack buffers in functions lo_export(), lo_read(), lo_lseek64(), and lo_tell64(). A malicious PostgreSQL server superuser can exploit this to send an arbitrarily large response, causing a stack buffer overflow on the client side. This can overwrite stack memory in client tools such as psql and pg_dump, potentially leading to arbitrary code execution. The vulnerability affects PostgreSQL versions before 18.4, 17.10, 16.14, 15.18, and 14.23. Exploitation requires user interaction in connecting to a malicious or compromised server. The CVSS v3.1 base score is 8.8 (high severity) with network attack vector, low complexity, high privileges required on the server, and user interaction required on the client. The scope is changed as the attack affects the client system. Red Hat and PostgreSQL have released patches addressing this issue.

Potential Impact

A malicious PostgreSQL server superuser can exploit this vulnerability to overwrite client stack memory when a client connects using vulnerable versions of libpq functions. This can lead to arbitrary code execution on the client system, compromising confidentiality, integrity, and availability. The vulnerability affects client tools such as psql and pg_dump. Exploitation requires the client to connect to a malicious or compromised server and involves user interaction. No known exploits in the wild have been reported at this time.

Mitigation Recommendations

A fix is available in PostgreSQL versions 18.4, 17.10, 16.14, 15.18, and 14.23 and later. Users should upgrade to these fixed versions or later. Until patched, users should avoid connecting to untrusted or potentially compromised PostgreSQL servers using psql, pg_dump, or other client tools that use the vulnerable libpq functions. The vendor advisory explicitly recommends only connecting to trusted servers as a mitigation. No other specific mitigations are noted.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
PostgreSQL
Date Reserved
2026-04-17T00:44:19.965Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-6477","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27718","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27743","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27742","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27738","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26181","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:29815","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:32994","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26561","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:29953","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26524","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:29904","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:32983","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26525","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:29212","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:28037","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26203","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:26204","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:27741","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21182","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22878","vendor":"Red Hat"}]

Threat ID: 6a05cfe8ec166c07b0e13947

Added to database: 05/14/2026, 13:36:40 UTC

Last enriched: 08/15/2026, 14:24:16 UTC

Last updated: 09/12/2026, 22:01:36 UTC

Views: 173

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses