StackRadar

CVE-2026-6477

High

Advisory

Published 14 May 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.005
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
270
of 17,781 indexed, latest versions
Container images
247
deployed by those charts
Fix available
10 of 14
affected packages

PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory

Carried by container images the latest versions of 270 of 17,781 indexed charts deploy, on 247 images.

Affected packageAffected versionsFixed inImages
postgresql-15deb15.3-0+deb12u1, 15.3-1.pgdg120+1, 15.4-2.pgdg120+1, 15.5-0+deb12u1+11 more15.18-0+deb12u1109
postgresql-17deb17.5-1, 17.5-1.pgdg130+1, 17.6-0+deb13u1, 17.6-1build1+5 more17.10-0+deb13u1, 17.10-0ubuntu0.25.10.130
postgresql-12deb12.7-0ubuntu0.20.04.1, 12.8-0ubuntu0.20.04.1, 12.9-0ubuntu0.20.04.1, 12.11-0ubuntu0.20.04.1+2 moreno fix listed17
postgresql-14deb14.3-1.pgdg22.04+1, 14.4-0ubuntu0.22.04.1, 14.5-0ubuntu0.22.04.1, 14.6-1.pgdg22.04+1+5 more14.23-0ubuntu0.22.04.113
postgresql18apk18.1-r0, 18.2-r0, 18.3-r018.4-r011
postgresql17apk17.2-r0, 17.4-r0, 17.5-r0, 17.6-r0+2 more17.10-r010
postgresql-10deb10.6-0ubuntu0.18.04.1, 10.10-0ubuntu0.18.04.1, 10.12-0ubuntu0.18.04.1, 10.14-0ubuntu0.18.04.1+1 moreno fix listed6
postgresql-16deb16.2-1ubuntu4, 16.6-0ubuntu0.24.04.1, 16.9-0ubuntu0.24.04.1, 16.10-0ubuntu0.24.04.1+1 more16.14-0ubuntu0.24.04.16
postgresql16apk16.3-r0, 16.9-r016.14-r05
postgresql-9.5deb9.5.10-0ubuntu0.16.04, 9.5.14-0ubuntu0.16.04no fix listed3
postgresql-9.3deb9.3.22-0ubuntu0.14.04no fix listed1
postgresqlbitnami11.8.0-10, 11.12.0-7, 14.4.0-0, 14.4.0-11+25 more14.23.030
PostgreSQLbitnami15.3.0, 15.4.0, 15.5.0-42, 16.0.0+6 more14.23.011
libpqrpm13.5-1.el9, 13.11-1.el9, 13.23-1.el9_70:13.23-3.el9_85
OSV records
ALPINE-CVE-2026-6477BIT-postgresql-2026-6477DEBIAN-CVE-2026-6477RHSA-2026:44308UBUNTU-CVE-2026-6477
Also known as
RHSA-2026:49909, USN-8294-1

Charts affected

270 by stars
ChartLatestAffected imagesRadar Score
verbasubstratusVerified publisher0.4.01 of 1See more

verba substratus 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
substratusai/verba:v0.4.0-baseURL261695be635eb
postgresql-15@15.6-0+deb12u1
15.18-0+deb12u1

Open the chart page →

13,390
freeradiussvtech-public-helm-charts0.1.51 of 4See more

freeradius svtech-public-helm-charts 0.1.5

1 of the 4 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
ptthanh1511/freeradius-server:3.0.26-netdebug5741cbde85ab
postgresql-12@12.12-0ubuntu0.20.04.1
no fix listed

Open the chart page →

12,655
cronjobt3n0.1.01 of 1See more

cronjob t3n 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
library/python:3.8d41127070014
postgresql-15@15.8-0+deb12u1
15.18-0+deb12u1

Open the chart page →

11,199
helm-testtest-helm-artifacthubVerified publisher1.0.01 of 2See more

helm-test test-helm-artifacthub 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
carlosmz87/test_helm_backend:latest8ffa63aa995d
postgresql-15@15.8-0+deb12u1
15.18-0+deb12u1

Open the chart page →

11,648
codegentest-opea1.0.01 of 5See more

codegen test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
opea/codegen-ui:1.02bee4eb66f3e
postgresql-15@15.6-0+deb12u1
15.18-0+deb12u1

Open the chart page →

28,814
codetranstest-opea1.0.01 of 5See more

codetrans test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
opea/codetrans-ui:1.03ef121f34610
postgresql-15@15.6-0+deb12u1
15.18-0+deb12u1

Open the chart page →

28,385
docsumtest-opea1.0.01 of 5See more

docsum test-opea 1.0.0

1 of the 5 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
opea/docsum-ui:1.07f854e9bffaf
postgresql-15@15.6-0+deb12u1
15.18-0+deb12u1

Open the chart page →

28,858
nextcloudth-chartsVerified publisher0.4.01 of 1See more

nextcloud th-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
library/nextcloud:31.0.6-apache588609d76b21
postgresql-15@15.13-0+deb12u1
15.18-0+deb12u1

Open the chart page →

10,086
owncloudth-chartsVerified publisher0.2.11 of 1See more

owncloud th-charts 0.2.1

1 of the 1 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
owncloud/server:10.15.051d9b74fc2a8
postgresql-12@12.19-0ubuntu0.20.04.1
no fix listed

Open the chart page →

10,006
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
14.23.0

Open the chart page →

5,535
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
postgresql-15@15.5-0+deb12u1
15.18-0+deb12u1

Open the chart page →

17,323
opencloudunxwaresVerified publisher0.2.31 of 13See more

opencloud unxwares 0.2.3

1 of the 13 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
apache/tika:2.9.2.1-fullae0b86d3c4d0
postgresql-16@16.2-1ubuntu4
16.14-0ubuntu0.24.04.1

Open the chart page →

45,239
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
postgresql-15@15.3-0+deb12u1
15.18-0+deb12u1

Open the chart page →

14,358
maybe-financevicsuferVerified publisher0.2.71 of 3See more

maybe-finance vicsufer 0.2.7

1 of the 3 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
ghcr.io/maybe-finance/maybe:0.5.0c6ab95ca9130
postgresql-15@15.10-0+deb12u1
15.18-0+deb12u1

Open the chart page →

10,795
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
postgresql-14@14.11-1.pgdg22.04+1
14.23-0ubuntu0.22.04.1

Open the chart page →

13,459
supersetwbstack0.1.01 of 1See more

superset wbstack 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
apache/superset:4.0.1ab9467fd712c
postgresql-15@15.6-0+deb12u1
15.18-0+deb12u1

Open the chart page →

7,085
giteawenerme12.7.01 of 4See more

gitea wenerme 12.7.0

1 of the 4 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
postgresql-15@15.13-0+deb12u1
15.18-0+deb12u1

Open the chart page →

8,811
wexa-studiowexa-studio1.2.01 of 15See more

wexa-studio wexa-studio 1.2.0

1 of the 15 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
postgresql17@17.5-r0
17.10-r0

Open the chart page →

14,983
keycloakwiremindVerified publisher25.3.11 of 2See more

keycloak wiremind 25.3.1

1 of the 2 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
14.23.0

Open the chart page →

7,624
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2026-6477.

Container imageDigestPackageFixed in
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
postgresql@16.6.0-1
14.23.0

Open the chart page →

11,577

Container images carrying it

247 by charts deploying them

A fixed version is listed for 10 of the 14 affected packages.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
postgresql@17.6.0-2
14.23.0
11
bitnamilegacy/postgresql:17.5.0:latest42a8200d3597
postgresql@17.5.0-14
14.23.0
5
bitnamilegacy/postgresql:16233f361c5819
postgresql@16.6.0-1
14.23.0
4
bitnamilegacy/postgresql:15.4.0-debian-11-r455dba7e6a514d
postgresql@15.4.0-6
PostgreSQL@15.4.0
14.23.0
14.23.0
4
bitnamilegacy/postgresql:17.6.0-debian-12-r0de520acd66fc
postgresql@17.6.0-0
14.23.0
4
bitnamilegacy/postgresql:15.3.0-debian-11-r7cc301eef7436
postgresql@15.3.0-3
PostgreSQL@15.3.0
14.23.0
14.23.0
3
bitnamilegacy/postgresql:14.13.0df6ec02e2b9a
postgresql@14.13.0-20
14.23.0
3
opencsghq/psql:latest57def8e77d0f
postgresql17@17.2-r0
17.10-r0
3
ghcr.io/bat-bs/bitnami-pgvector:pg1619ebe07b4daf
postgresql@16.6.0-1
14.23.0
3
quay.io/devtron/notifier:9804331c-372-39294709c7da19c5a
postgresql-15@15.14-0+deb12u1
15.18-0+deb12u1
3
apache/tika:2.9.2.1-fullae0b86d3c4d0
postgresql-16@16.2-1ubuntu4
16.14-0ubuntu0.24.04.1
2
bitnamilegacy/pgpool:4.6.3-debian-12-r0d3bf3910f148
postgresql-15@15.13-0+deb12u1
15.18-0+deb12u1
2
bitnamilegacy/postgresql:14.4.0-debian-11-r237e7ebb082031
postgresql@14.4.0-11
14.23.0
2
bitnamilegacy/postgresql:16.4.0-debian-12-r1494bc968141e7
postgresql@16.4.0-12
14.23.0
2
fireflyiii/core:version-6.5.9fe4ecec4c2ba
postgresql-17@17.8-0+deb13u1
17.10-0+deb13u1
2
fireflyiii/data-importer:version-2.2.3ab52bf932546
postgresql-17@17.9-0+deb13u1
17.10-0+deb13u1
2
freeradius/freeradius-server:3.0.2121c8bfa904d8
postgresql-10@10.12-0ubuntu0.18.04.1
no fix listed
2
gjeanmart/safe-ganache-node:latest926264c8f2d1
postgresql-15@15.3-0+deb12u1
15.18-0+deb12u1
2
kurento/kurento-media-server:latest03c0d34d0828
postgresql-16@16.10-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1
2
library/python:3.7eedf63967cdb
postgresql-15@15.3-0+deb12u1
15.18-0+deb12u1
2
moreillon/user-manager:v5.0.2e1c9bfab5c16
postgresql-15@15.5-0+deb12u1
15.18-0+deb12u1
2
omecproject/mcord-synchronizer:comac-1.0.0cfdb566dd949
postgresql-9.5@9.5.14-0ubuntu0.16.04
no fix listed
2
opendatacube/ows:latest668cbb41473c
postgresql-16@16.6-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1
2
qichenxu4pd/pythonexample:1.0f3a8502bc21b
postgresql-15@15.6-0+deb12u1
15.18-0+deb12u1
2
ghcr.io/codingducksrl/laravel:8.15be52524664c
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1
2
ghcr.io/danbooru/danbooru:9cab67c0ac72a8c52289302c519715ceec2372d95f545698e907
postgresql-14@14.5-0ubuntu0.22.04.1
14.23-0ubuntu0.22.04.1
2
ghcr.io/postgresml/pgcat:main245f9d2f5f5b
postgresql-15@15.5-0+deb12u1
15.18-0+deb12u1
2
akaunting/akaunting:3.0.1552811b36ec3a
postgresql-15@15.3-0+deb12u1
15.18-0+deb12u1
1
alpine/psql:18.339824ef2b7fc
postgresql18@18.3-r0
18.4-r0
1
ankane/pgvector:v0.5.1d3a9d8ac27bb
postgresql-15@15.4-2.pgdg120+1
15.18-0+deb12u1
1
apache/superset:4.0.1ab9467fd712c
postgresql-15@15.6-0+deb12u1
15.18-0+deb12u1
1
appwrite/appwrite:1.9.01aaa70127114
postgresql18@18.2-r0
18.4-r0
1
arthurjguerra18/revwallet:v0.7.12f540af20b307
postgresql-15@15.8-0+deb12u1
15.18-0+deb12u1
1
arunvelsriram/utils:latest655ad18fd8d6
postgresql-16@16.9-0ubuntu0.24.04.1
16.14-0ubuntu0.24.04.1
1
assistiot/smart-orchestrator_scheduler_mc:latestb1dbe4d62a03
postgresql-15@15.3-0+deb12u1
15.18-0+deb12u1
1
avinash263/pyredis263:latestaa2b8727f1a6
postgresql-15@15.3-0+deb12u1
15.18-0+deb12u1
1
baserow/backend:1.31.1e0b3c8130b91
postgresql-15@15.10-0+deb12u1
15.18-0+deb12u1
1
baserow/baserow:1.30.1df0c42eb67e8
postgresql-15@15.10-1.pgdg120+1
15.18-0+deb12u1
1
beyzkaya/blog-backend:v1.0.112a6a3d1c5f9
postgresql-15@15.13-0+deb12u1
15.18-0+deb12u1
1
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
postgresql-15@15.13-0+deb12u1
15.18-0+deb12u1
1
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
postgresql@16.4.0-10
14.23.0
1
bitnamilegacy/postgresql:16.1.0-debian-11-r2504f3b0dfdb15
postgresql@16.1.0-34
PostgreSQL@16.1.0-34
14.23.0
14.23.0
1
bitnamilegacy/postgresql:16.1.0-debian-11-r1529e3dd0e7e7a
postgresql@16.1.0-14
PostgreSQL@16.1.0
14.23.0
14.23.0
1
bitnamilegacy/postgresql:16.3.0-debian-12-r43332e81afb4f
postgresql@16.3.0-3
PostgreSQL@16.3.0-3
14.23.0
14.23.0
1
bitnamilegacy/postgresql:16.4.03ba6e6f11388
postgresql@16.4.0-20
14.23.0
1
bitnamilegacy/postgresql:15.2.0-debian-11-r113e65a6b89e38
postgresql@15.2.0-4
14.23.0
1
bitnamilegacy/postgresql:15.3.0-debian-11-r775f4cf61668e5
postgresql@15.3.0-9
PostgreSQL@15.3.0
14.23.0
14.23.0
1
bitnamilegacy/postgresql:17.5.0-debian-12-r16687034f33da6
postgresql@17.5.0-11
14.23.0
1
bitnamilegacy/postgresql:15.5.06887635cc793
postgresql@15.5.0-42
PostgreSQL@15.5.0-42
14.23.0
14.23.0
1
bitnamilegacy/postgresql:17.5.0-debian-12-r1285198aae0aed
postgresql@17.5.0-9
14.23.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.