CVE-2026-6479
PostgreSQL: uncontrolled recursion in SSL and GSS negotiation causes denial of service
Technology
PostgreSQL
CVSS Score
7.5 / 10.0
Affected Versions
Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed)
Upstream Fix
18.4; 17.10; 16.14; 15.18; 14.23
Published
May 14, 2026
OSSeva Coverage
Fixed upstream
Description
Uncontrolled recursion in SSL and GSS negotiation let an attacker who can connect to the PostgreSQL Unix socket cause a sustained denial of service. With SSL and GSS both disabled, the same works through the TCP port. Scored 7.5 by PostgreSQL as the CNA. Fixed in 18.4, 17.10, 16.14, 15.18 and 14.23.
Is your PostgreSQL deployment affected?
If you're running Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.