CVE-2026-6478: Timing Channel in PostgreSQL MD5 Passwords
On May 14, 2026, PostgreSQL released security fixes for versions 18.4, 17.10, 16.14, 15.18, and 14.23. Among the vulnerabilities fixed is CVE-2026-6478, described by the project as a timing side channel in MD5 password comparison during authentication. ...