← Vulnerability feed

Vulnerability record · CVE-2026-6477 · published 14 May 2026

CVE-2026-6477: Postgresql classic buffer overflow vulnerability

Postgresql · Postgresql

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

8.8 CVSS 3.1 High EPSS 0.45% · top 63.1% CWE-242 · CWE-242CWE-120 · Classic buffer overflow
8.8CVSS 3.1 base score
0.45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
46References
25 Aug 2026Last modified by NVD

Description

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.postgresql.org/support/security/CVE-2026-6477/ PatchVendor Advisory
https://access.redhat.com/errata/RHSA-2026:21182
https://access.redhat.com/errata/RHSA-2026:22878
https://access.redhat.com/errata/RHSA-2026:26181
https://access.redhat.com/errata/RHSA-2026:26203
https://access.redhat.com/errata/RHSA-2026:26204
https://access.redhat.com/errata/RHSA-2026:26524
https://access.redhat.com/errata/RHSA-2026:26525
https://access.redhat.com/errata/RHSA-2026:26561
https://access.redhat.com/errata/RHSA-2026:27718
https://access.redhat.com/errata/RHSA-2026:27738
https://access.redhat.com/errata/RHSA-2026:27741
https://access.redhat.com/errata/RHSA-2026:27742
https://access.redhat.com/errata/RHSA-2026:27743
https://access.redhat.com/errata/RHSA-2026:28037
https://access.redhat.com/errata/RHSA-2026:28143
https://access.redhat.com/errata/RHSA-2026:28208
https://access.redhat.com/errata/RHSA-2026:28999
https://access.redhat.com/errata/RHSA-2026:29212
https://access.redhat.com/errata/RHSA-2026:29815
https://access.redhat.com/errata/RHSA-2026:29904
https://access.redhat.com/errata/RHSA-2026:29953
https://access.redhat.com/errata/RHSA-2026:32983
https://access.redhat.com/errata/RHSA-2026:32994
https://access.redhat.com/errata/RHSA-2026:33441
https://access.redhat.com/errata/RHSA-2026:33497
https://access.redhat.com/errata/RHSA-2026:34043
https://access.redhat.com/errata/RHSA-2026:34362
https://access.redhat.com/errata/RHSA-2026:34363
https://access.redhat.com/errata/RHSA-2026:35880
https://access.redhat.com/errata/RHSA-2026:42555
https://access.redhat.com/errata/RHSA-2026:44308
https://access.redhat.com/errata/RHSA-2026:44391
https://access.redhat.com/errata/RHSA-2026:44420
https://access.redhat.com/errata/RHSA-2026:44481
https://access.redhat.com/errata/RHSA-2026:47090
https://access.redhat.com/errata/RHSA-2026:49521
https://access.redhat.com/errata/RHSA-2026:49908
https://access.redhat.com/errata/RHSA-2026:49909
https://access.redhat.com/errata/RHSA-2026:50779

Track CVE-2026-6477 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-1902Postgresql vulnerabilityPostgreSQL, 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 generates insecure temporary fi…EPSS 2.2%10.0CVE-2013-1903Postgresql permissions and access controls vulnerabilityPostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly provides t…EPSS 2.2%10.0CVE-2007-3279Postgresql vulnerabilityPostgreSQL 8.1 and probably later versions, when the PL/pgSQL (plpgsql) language has been created, grants certain plpgsql privileges to the PUBLIC do…EPSS 2.6%10.0CVE-2002-1399Postgresql vulnerabilityUnknown vulnerability in cash_out and possibly other functions in PostgreSQL 7.2.1 and earlier, and possibly later versions before 7.2.3, with unknow…EPSS 1.8%9.8CVE-2015-0244Postgresql sql injection vulnerabilityPostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 does not properly handle errors while …EPSS 4.4%9.8CVE-2015-3166Postgresql memory buffer overflow vulnerabilityThe snprintf implementation in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 does no…EPSS 4.6%9.8CVE-2019-10211Postgresql code injection vulnerabilityPostgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected di…EPSS 1.8%9.8CVE-2018-16850Postgresql sql injection vulnerabilitypostgresql before versions 11.1, 10.6 is vulnerable to a to SQL injection in pg_upgrade and pg_dump via CREATE TRIGGER ... REFERENCING. Using a purpo…EPSS 5.1%

Source: NIST National Vulnerability Database (record CVE-2026-6477), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.