CVE-2023-5870: PostgreSQL vulnerability analysis and mitigation
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.
Source: NVD
Related PostgreSQL vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-6638
HIGH
8.8
PostgreSQL
postgresql16-upgrade-debuginfo
No
Yes
May 14, 2026
CVE-2026-6637
HIGH
8.8
PostgreSQL
postgresql-plperl
No
Yes
May 14, 2026
CVE-2026-6479
HIGH
7.5
PostgreSQL
postgresql17-private-devel
No
Yes
May 14, 2026
CVE-2026-6478
MEDIUM
6.5
PostgreSQL
postgresql18-private-libs
No
Yes
May 14, 2026
CVE-2026-6575
MEDIUM
4.3
PostgreSQL
postgresql-docs
No
Yes
May 14, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.