security2 distinct publishers
Any PostgreSQL replication account can load a shared library as the postgres OS user
CVE-2026-6471 has sat in every PostgreSQL release since 9.4 shipped in 2014. Cyera says the plugin name in a replication slot request reaches dlopen() unvalidated, which makes the fix a privilege audit as much as a patch.
Reality
- Evidence62
- Adoption38
- Hype gap+15
- Incentives66