CVE Vulnerabilities

CVE-2026-6479

Uncontrolled Recursion

Published: May 14, 2026 | Modified: Jun 17, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Weakness

The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.

Affected Software

NameVendorStart VersionEnd Version
PostgresqlPostgresql*14.23 (excluding)
PostgresqlPostgresql15.0 (including)15.18 (excluding)
PostgresqlPostgresql16.0 (including)16.14 (excluding)
PostgresqlPostgresql17.0 (including)17.10 (excluding)
PostgresqlPostgresql18.0 (including)18.4 (excluding)
Red Hat Enterprise Linux 10RedHatpostgresql18-0:18.4-1.el10_2*
Red Hat Enterprise Linux 10RedHatpostgresql16-0:16.14-1.el10_2*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatpostgresql16-0:16.14-1.el10_0*
Red Hat Enterprise Linux 8RedHatpostgresql:15-8100020260605152259.489197e6*
Red Hat Enterprise Linux 8RedHatpostgresql:16-8100020260530205218.489197e6*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatpostgresql:15-8080020260615085052.63b34585*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatpostgresql:15-8080020260615085052.63b34585*
Red Hat Enterprise Linux 9RedHatpostgresql:16-9080020260605131007.rhel9*
Red Hat Enterprise Linux 9RedHatpostgresql:18-9080020260605125734.rhel9*
Red Hat Enterprise Linux 9RedHatpostgresql:15-9080020260605124405.rhel9*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatpostgresql:15-9020020260625101129.rhel9*
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRedHatpostgresql:16-9040020260612132455.rhel9*
Red Hat Enterprise Linux 9.4 Update Services for SAP SolutionsRedHatpostgresql:15-9040020260616071806.rhel9*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatpostgresql:16-9060020260612084605.rhel9*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatpostgresql:15-9060020260622062902.rhel9*
Red Hat Ansible Automation Platform 2.2RedHatansible-automation-platform/bootc-automation-portal-rhel9:1784804630*
Red Hat Hardened ImagesRedHatpostgresql17-main-17.10-0.1.hum1*
Red Hat Hardened ImagesRedHatpostgresql18-main-18.4-0.1.hum1*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1784795076*
Postgresql-10Ubuntuupstream*
Postgresql-12Ubuntuupstream*
Postgresql-14Ubuntujammy*
Postgresql-16Ubuntunoble*
Postgresql-17Ubuntuquesting*
Postgresql-18Ubuntudevel*
Postgresql-18Ubunturesolute*
Postgresql-9.3Ubuntuupstream*
Postgresql-9.5Ubuntuupstream*

Potential Mitigations

References