CVE-2026-6474: PostgreSQL timeofday() can disclose portions of server memory
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Other sources
PostgreSQL timeofday() can disclose portions of server memory
— Microsoft
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6474?
CVE-2026-6474 has a medium severity level as it allows attackers to potentially retrieve sensitive portions of server memory.
How do I fix CVE-2026-6474?
To mitigate CVE-2026-6474, upgrade your PostgreSQL server to version 18.4 or later.
What versions are affected by CVE-2026-6474?
CVE-2026-6474 affects PostgreSQL versions prior to 18.4, 17.10, 16.14, 15.18, and 14.23.
Can CVE-2026-6474 be exploited remotely?
Yes, CVE-2026-6474 can be exploited remotely if an attacker can control the crafted timezone zones.
What type of attack does CVE-2026-6474 represent?
CVE-2026-6474 represents a format string vulnerability that can lead to information disclosure.