FR
live
tag

#postgresql

CVE-2026-6471 lets a PostgreSQL replication account run code as the system user

Present since PostgreSQL 9.4 in 2014, CVE-2026-6471 (CVSS 7.2) lets an account holding the REPLICATION attribute load an arbitrary library through logical decoding and run code as the server’s operating-system user. Fixed on August 13, 2026 via the output_plugin_libraries parameter: update and make sure your output plugins are explicitly allowlisted.

PostgreSQL ships 28 security fixes in one go and puts version 14 on the clock

On August 13, 2026, the PostgreSQL project released 18.6, 17.11, 16.15, 15.19, 14.24 and 19 Beta 3, fixing 28 security vulnerabilities — a record — including a dozen memory bugs exploitable for code execution. Apply the minor release now, and if you are still on version 14, plan the major upgrade before November 12, 2026.

Type at least two characters.

navigate open esc dismiss