Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-6473

PostgreSQL: integer wraparound makes the server undersize allocations

Technology

PostgreSQL

CVSS Score

8.8 / 10.0

Affected Versions

Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed)

Upstream Fix

18.4; 17.10; 16.14; 15.18; 14.23

Published

May 14, 2026

OSSeva Coverage

Fixed upstream

Description

Integer wraparound in several server features let an unprivileged database user make the server undersize an allocation and write out of bounds, which may execute arbitrary code as the operating system user running the database. Applications that pass gigabyte-scale user input to the affected functions can also be made to crash. Scored 8.8 by PostgreSQL as the CNA. Fixed in 18.4, 17.10, 16.14, 15.18 and 14.23.

Upstream record: NVD · CVE.org

Is your PostgreSQL deployment affected?

If you're running Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.