CVE-2026-6478Patch(postgresql / postgresql)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch postgresql postgresql systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-385

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postgresql

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-06-23); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
postgresql

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 106-2306-24
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🛡️ RLSA-2026:28208: CVE-2026-6478 no PostgreSQL (MD5 timing attack) corrigido no Rocky Linux 8. Atualize já: dnf update postgresql\* pgaudit pg_repack postgres-decoderbufs e reinicie o serviço. Saiba mais: -> https://tinyurl.com/mkk46nv6 #RockyLinux https://t.co/oTSVj2rDsU

    Post summary

    The tweet announces that CVE‑2026‑6478, a PostgreSQL MD5 timing attack, has been patched in Rocky Linux 8, and provides specific update commands and a link for more details.

    1000078
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 ATENÇÃO SysAdmins! RLSA-2026:28143 corrige falhas CRÍTICAS no PostgreSQL 16/Rocky 8: CVE-2026-6473 (RCE) e CVE-2026-6478 (timing attack). Saiba mais: -> http://tinyurl.com/u5jet86v https://t.co/LvL0iwIct4

    Post summary

    The tweet announces a patch (RLSA‑2026:28143) that addresses two critical CVEs affecting PostgreSQL 16 on Rocky 8, specifying the vulnerability types (RCE and timing attack) and providing a link for further details.

    1000076
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppostgresqlpostgresql---

Explore more