CVE-2026-6637Disclosure(postgresql / postgresql)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch postgresql postgresql systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as the operating system user running the database. A distinct attack is possible if the application declares a user-controlled column as a "refint" cascade primary key and facilitates user-controlled updates to that column. In that case, a SQL injection allows a primary key update value provider to execute arbitrary SQL as the database user performing the primary key update. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postgresql

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-14); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
postgresql

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-14: 2Mentions · 2026-05-21: 1Mentions · 2026-05-26: 1Patch / Workaround · 2026-05-14: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-05-14: 2Technical Details · 2026-05-21: 105-1405-2105-26
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-142
Disclosure2
2026-05-211
Patch1
2026-05-261
General1
Full discourse4 posts
  • Nik Samokhvalov@samokhvalov
    General

    my first CVE https://www.postgresql.org/support/security/CVE-2026-6637/ https://www.cve.org/CVERecord?id=CVE-2026-6637 mixed feelings – CVE counts are spiking everywhere, are we're at the beginning of tsunami for FOSS? upgrade sooner

    Post summary

    The post points to CVE-2026-6637 by linking to the official pages and comments on the growing number of CVEs, but it does not provide technical details, exploitation information, or mitigation steps.

    1301921.9K
    12.4K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    New PostgreSQL vulnerabilities were disclosed today, including issues related to code execution, SQL injection, and denial of service. Worth reviewing: • CVE-2026-6637 – potential code execution via refint • CVE-2026-6476 – SQL injection in pg_createsubscriber • CVE-2026-6479 – DoS in SSL/GSS negotiation PostgreSQL teams may want to review affected versions and patch guidance. https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/

    Post summary

    Three new PostgreSQL CVEs have been disclosed, detailing code execution, SQL injection, and DoS vulnerabilities, with recommended patch guidance for affected versions.

    00131598
    255 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    PostgreSQLが11件の脆弱性を修正、CVE-2026-6637など危険度度が高い脆弱性に注意-PostgreSQL 14は2026年11月にEOLへ https://rocket-boys.co.jp/security-measures-lab/postgresql-11-vulnerabilities-fixed-cve-2026-6637/ #セキュリティ対策Lab #security #securitynews

    Post summary

    PostgreSQL has released patches for 11 vulnerabilities, including the high‑severity CVE‑2026‑6637, and encourages users to update before the upcoming EOL of PostgreSQL 14.

    00000148
    407 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-6637 Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as t… CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-6637 #PostgreSQL #CyberSecurity #InfoSec

    Post summary

    A stack buffer overflow vulnerability (CVE‑2026‑6637) in PostgreSQL's "refint" module has been disclosed, allowing unprivileged database users to execute arbitrary code, with no current evidence of exploitation or available patch.

    0000036
    90 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppostgresqlpostgresql---

Explore more