Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-6479

PostgreSQL: uncontrolled recursion in SSL and GSS negotiation causes denial of service

Technology

PostgreSQL

CVSS Score

7.5 / 10.0

Affected Versions

Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed)

Upstream Fix

18.4; 17.10; 16.14; 15.18; 14.23

Published

May 14, 2026

OSSeva Coverage

Fixed upstream

Description

Uncontrolled recursion in SSL and GSS negotiation let an attacker who can connect to the PostgreSQL Unix socket cause a sustained denial of service. With SSL and GSS both disabled, the same works through the TCP port. Scored 7.5 by PostgreSQL as the CNA. Fixed in 18.4, 17.10, 16.14, 15.18 and 14.23.

Upstream record: NVD · CVE.org

Is your PostgreSQL deployment affected?

If you're running Before 18.4, 17.10, 16.14, 15.18 and 14.23 (supported versions only; 13 and older not assessed), you need this patch. Book a discovery call to get covered.