All findings

CVE-2026-6479 high

PostgreSQL credits Calif.io and Claude for SSL/GSS recursion DoS

PostgreSQL's May 2026 security release credits Calif.io in collaboration with Claude and Anthropic Research for CVE-2026-6479, an SSL/GSS initialization recursion denial of service.

Bug class
SSL/GSS initialization recursion denial of service
Affected codebase
PostgreSQL
Credited system
Claude / Anthropic Research
Disclosed
May 14, 2026
Attribution
Direct source attribution
Severity
high
Source status: PostgreSQL's release and CVE page directly thank Calif.io in collaboration with Claude and Anthropic Research for reporting CVE-2026-6479. The public score is CVSS 7.5 high.

Summary

CVE-2026-6479 is a PostgreSQL denial-of-service issue in SSL/GSS initialization that can trigger uncontrolled recursion. PostgreSQL rates it CVSS 7.5 high and lists supported vulnerable versions 14 through 18 before the May 2026 releases.

Attribution

The PostgreSQL project directly credits Calif.io in collaboration with Claude and Anthropic Research for reporting the issue, making this a clean direct-attribution entry.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.