Back

HIGH

PostgreSQL discloses MD5-hashed passwords via covert timing channel

Published May 14, 2026

Description

Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover user credentials sufficient to authenticate. This does not affect scram-sha-256 passwords, the default in all supported releases. However, current databases may have MD5-hashed passwords originating in upgrades from PostgreSQL 13 or earlier. Versions before PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.

Affected products

Remediation

Vendor solution

reset password with password_encryption=scram-sha-256

Red Hat mitigation

To mitigate this vulnerability, ensure that all PostgreSQL user passwords are not hashed using MD5. Users should migrate to stronger hashing algorithms such as `scram-sha-256`. This can be achieved by altering user passwords, which will automatically update their hash to the currently configured default. For example, to change a user's password: `ALTER USER username WITH PASSWORD 'new_password';` This action will require users to re-authenticate. If a service relies on these credentials, it may require a restart to pick up the new authentication details.

Weaknesses (1)

References (40)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PostgreSQL
Published May 14, 2026
Updated Aug 25, 2026
Reserved Apr 17, 2026
CISA Vulnrichment
Updated May 14, 2026
NVD
Status Modified
Modified Aug 25, 2026
Red Hat
Severity Important
Public date May 14, 2026