Information Exposure Through Timing Discrepancy in PostgreSQL - CVE-2026-6478
Published: May 14, 2026
PostgreSQL
Detailed vulnerability description
The vulnerability allows a remote attacker to recover credentials sufficient to authenticate.
The vulnerability exists due to observable timing discrepancies in MD5-hashed password comparison during authentication. A remote attacker can measure authentication timing to recover credentials sufficient to authenticate.
The issue does not affect scram-sha-256 passwords and applies to MD5-hashed passwords that may originate from upgrades from PostgreSQL 13 or earlier.