<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve on sharedbuffers</title><link>https://sharedbuffers.com.br/en/tags/cve/</link><description>Recent content in Cve on sharedbuffers</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 07 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://sharedbuffers.com.br/en/tags/cve/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-6478: Timing Channel in PostgreSQL MD5 Passwords</title><link>https://sharedbuffers.com.br/en/posts/cve-2026-6478-postgresql-md5-timing/</link><pubDate>Tue, 07 Jul 2026 00:00:00 +0000</pubDate><guid>https://sharedbuffers.com.br/en/posts/cve-2026-6478-postgresql-md5-timing/</guid><description>&lt;!-- Translation notes:
- "canal lateral de tempo" → "timing side channel" / "timing channel" (standard security term)
- "verificador de senha" → "password verifier" (matches PostgreSQL docs terminology for rolpassword)
- SQL CASE labels ('sem senha', 'MD5', 'SCRAM', 'outro') translated to English since they are display output, not stored data
- "oráculo de tempo" → "timing oracle" (standard cryptanalysis term)
- "legado" → "legacy"
--&gt;
&lt;br&gt;
&lt;p&gt;On May 14, 2026, PostgreSQL released security fixes for versions 18.4, 17.10, 16.14, 15.18, and 14.23. Among the vulnerabilities fixed is CVE-2026-6478, described by the project as a timing side channel in MD5 password comparison during authentication.&lt;/p&gt;</description></item></channel></rss>