Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-606

JLSEC-2026-606

JLSEC Published
Modified
Affected Packages
LibPQ_jll < 16.14.0+0
Aliases / Upstream
CVE-2026-6479

Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX socket to achieve sustained denial of service. If SSL and GSS are both disabled, an attacker can do the same via access to a PostgreSQL TCP socket. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

References