V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2026-6474
ANC
Medium

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafte…

CVSS
4.3
Medium
EPSS
0.00
p9
Published
2026-01-01
Updated
2026-01-01
Description

Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Tags · CWE
CWE-134
CAPEC-67
CAPEC-135
Affected products
Postgresql < 14.23Postgresql 15.0–15.18Postgresql 16.0–16.14Postgresql 17.0–17.10Postgresql 18.0–18.4
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Timeline
2026-01-01
Published
2026-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.000 · p9
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
Tracked
postgresql-13Tracked
postgresql-15Tracked
postgresql-17Tracked
postgresql-18Tracked
postgresql*Tracked
Source databases
ANC
DEB
CVE
Related vulnerabilities