PostgreSQL Security Update (MINDBREEZE42880)

ID: MINDBREEZE42880 
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS 
Severity: 8.8 High 
Status: Final 
First published: August 5, 2026 
CVEs: CVE-2026-6473, CVE-2026-6472, CVE-2026-6474, CVE-2026-6475, CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6575, CVE-2026-6637, CVE-2026-6638 

Summary 

  • PostgreSQL `CREATE TYPE` does not check `multirange` schema `CREATE` privilege 
  • PostgreSQL server undersizes allocations, via integer wraparound 
  • PostgreSQL `timeofday()` can disclose portions of server memory 
  • PostgreSQL `pg_basebackup` and `pg_rewind` can overwrite unrelated files of origin superuser choice 
  • PostgreSQL `pg_createsubscriber` allows SQL injection via subscription name 
  • PostgreSQL `libpq` lo_* functions let server superuser overwrite client stack memory 
  • PostgreSQL discloses MD5-hashed passwords via covert timing channel 
  • PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion 
  • PostgreSQL `pg_restore_attribute_stats` accepts values that cause query planning to read past end of stats array 
  • PostgreSQL `refint` allows stack buffer overflow and SQL injection 
  • PostgreSQL `REFRESH PUBLICATION` allows SQL injection via table name 

 

Hotfix Information 

Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS: 

  • Mindbreeze InSpire 26.4 Release
  • Mindbreeze InSpire SaaS 26.4 Release