THREAT OPS › Threat News › [NVD] CVE-2026-6477 (HIGH 8.8) — Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., resu
[NVD] CVE-2026-6477 (HIGH 8.8) — Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., resu
CVE-2026-6477 CVSS: 8.8 HIGH Published: 2026-05-14T14:16:25.347
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-deter
Indicators of compromise
- CVE-2026-6477cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-6477