CVE-2026-6477
Published: 14 May 2026
Summary
CVE-2026-6477 is a high-severity Use of Inherently Dangerous Function (CWE-242) vulnerability in Postgresql (inferred from references). Its CVSS base score is 8.8 (High).
Operationally, it is not currently listed in the CISA KEV catalog.
NVD Description
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-determined data…
more
into a buffer of unspecified size. Because both the \lo_export command in psql and pg_dump call lo_read(), the server superuser can overwrite pg_dump or psql stack memory. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Deeper analysisAI
Automated synthesis unavailable for this CVE.
Details
- CWE(s)