THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-6477 (HIGH 8.8) — Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., resu

[NVD] CVE-2026-6477 (HIGH 8.8) — Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., resu

lownvdPublished 2026-05-14

CVE-2026-6477 CVSS: 8.8 HIGH Published: 2026-05-14T14:16:25.347

Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length, server-deter

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-6477