Source status: PostgreSQL's release and CVE page directly thank Calif.io in collaboration with Claude and Anthropic Research for reporting CVE-2026-6479. The public score is CVSS 7.5 high.
Summary
CVE-2026-6479 is a PostgreSQL denial-of-service issue in SSL/GSS initialization that can trigger uncontrolled recursion. PostgreSQL rates it CVSS 7.5 high and lists supported vulnerable versions 14 through 18 before the May 2026 releases.
Attribution
The PostgreSQL project directly credits Calif.io in collaboration with Claude and Anthropic Research for reporting the issue, making this a clean direct-attribution entry.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.