Format string error in PostgreSQL - CVE-2026-6474
Published: May 14, 2026
PostgreSQL
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to an externally-controlled format string in the timeofday() function when processing crafted timezone zones. A remote user can supply a crafted timezone zone to disclose sensitive information.
The issue can expose portions of server memory.