CVE-2023-5870: PostgreSQL vulnerability analysis and mitigation
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension with a less-resilient background worker and would affect that specific background worker only. This issue may allow a remote high privileged user to launch a denial of service (DoS) attack.
Source: NVD
Related PostgreSQL vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-6464
HIGH
8.1
PostgreSQL
cpe:2.3:a:postgresql:postgresql
No
Yes
Aug 13, 2026
CVE-2026-73515
HIGH
7.2
PostgreSQL
postgis-client
No
Yes
Aug 13, 2026
CVE-2026-6471
HIGH
7.2
PostgreSQL
postgresql-17
No
Yes
Aug 13, 2026
CVE-2026-6470
MEDIUM
4.3
PostgreSQL
cpe:2.3:a:postgresql:postgresql
No
Yes
Aug 13, 2026
CVE-2026-6469
LOW
3.8
PostgreSQL
postgresql-13
No
Yes
Aug 13, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.