All findings

CVE-2026-6473, CVE-2026-6474 high

PostgreSQL May 2026 release credits Xint Code on two CVEs

PostgreSQL's May 14, 2026 release credits Xint Code for a high-severity allocation-size issue and a timeofday() memory disclosure.

Bug class
Server memory corruption and memory disclosure
Affected codebase
PostgreSQL
Credited system
Xint Code
Disclosed
May 14, 2026
Attribution
Direct source attribution
Severity
high
Source status: The PostgreSQL project directly thanks Xint Code for CVE-2026-6474 and includes Xint Code among reporters for CVE-2026-6473. CVE-2026-6473 is shared with additional researchers and organizations.

Summary

PostgreSQL’s May 14, 2026 release includes two Xint Code credits:

Attribution

The PostgreSQL release and per-CVE pages provide the accepted upstream public credits. CVE-2026-6473 is a shared credit; CVE-2026-6474 is directly credited to Xint Code.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.