Source status: The PostgreSQL project directly thanks Xint Code for CVE-2026-6474 and includes Xint Code among reporters for CVE-2026-6473. CVE-2026-6473 is shared with additional researchers and organizations.
Summary
PostgreSQL’s May 14, 2026 release includes two Xint Code credits:
- CVE-2026-6473, a high-severity allocation-size issue where integer wraparound can cause undersized server allocations.
- CVE-2026-6474, a
timeofday()issue that can disclose portions of server memory via crafted timezone zones.
Attribution
The PostgreSQL release and per-CVE pages provide the accepted upstream public credits. CVE-2026-6473 is a shared credit; CVE-2026-6474 is directly credited to Xint Code.
References
- PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 release
- PostgreSQL: CVE-2026-6473
- PostgreSQL: CVE-2026-6474
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.