PostgreSQL timeofday() FS Vulnerability (pre-18.4,17.10,16.14,15.18,14.23)
CVE-2026-6474 Published on May 14, 2026
PostgreSQL timeofday() can disclose portions of server memory
Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server memory, via crafted timezone zones. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.
Weakness Type
Use of Externally-Controlled Format String
The software uses a function that accepts a format string as an argument, but the format string originates from an external source.
Products Associated with CVE-2026-6474
stack.watch emails you whenever new vulnerabilities are published in Canonical Ubuntu Linux or PostgreSQL. Just hit a watch button to start following.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.