Back to the feed

~/article/postgresql-fixes-12-year-old-logical-decoding-flaw-enabling-replication-1fsuta
infoSource: The Hacker News

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are

Read at the source

Summary written for cymesh.dev. The full article lives at The Hacker News.

Referenced CVEs

Topics

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/postgresql-fixes-12-year-old-logical-decoding-flaw-enabling-replication-1fsuta