CVE-2026-6473
PostgreSQL: integer wraparound makes the server undersize allocations
Technology
PostgreSQL
CVSS Score
8.8 / 10.0
Affected Versions
Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed)
Upstream Fix
18.4; 17.10; 16.14; 15.18; 14.23
Published
May 14, 2026
OSSeva Coverage
Fixed upstream
Description
Integer wraparound in several server features let an unprivileged database user make the server undersize an allocation and write out of bounds, which may execute arbitrary code as the operating system user running the database. Applications that pass gigabyte-scale user input to the affected functions can also be made to crash. Scored 8.8 by PostgreSQL as the CNA. Fixed in 18.4, 17.10, 16.14, 15.18 and 14.23.
Is your PostgreSQL deployment affected?
If you're running Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.