PostgreSQL Security Update (MINDBREEZE42880)
ID: MINDBREEZE42880
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS
Severity: 8.8 High
Status: Final
First published: August 5, 2026
CVEs: CVE-2026-6473, CVE-2026-6472, CVE-2026-6474, CVE-2026-6475, CVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479, CVE-2026-6575, CVE-2026-6637, CVE-2026-6638
Summary
- PostgreSQL `CREATE TYPE` does not check `multirange` schema `CREATE` privilege
- PostgreSQL server undersizes allocations, via integer wraparound
- PostgreSQL `timeofday()` can disclose portions of server memory
- PostgreSQL `pg_basebackup` and `pg_rewind` can overwrite unrelated files of origin superuser choice
- PostgreSQL `pg_createsubscriber` allows SQL injection via subscription name
- PostgreSQL `libpq` lo_* functions let server superuser overwrite client stack memory
- PostgreSQL discloses MD5-hashed passwords via covert timing channel
- PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion
- PostgreSQL `pg_restore_attribute_stats` accepts values that cause query planning to read past end of stats array
- PostgreSQL `refint` allows stack buffer overflow and SQL injection
- PostgreSQL `REFRESH PUBLICATION` allows SQL injection via table name
Hotfix Information
Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS:
- Mindbreeze InSpire 26.4 Release
- Mindbreeze InSpire SaaS 26.4 Release