Vulnerability Management4 September 2026
PostgreSQL Patches 12-Year-Old Logical Decoding Flaw (CVE-2026-6471)
A missing authorization check in PostgreSQL's logical decoding, present since 2014, let any account with the REPLICATION attribute run arbitrary code as the database's OS user. Patches shipped August 13, 2026.
postgresqlcve-2026-6471database-security
4 min readRead
DevSecOps & Infrastructure14 July 2026
Lobste.rs moves to SQLite: a lesson in shrinking your attack surface
The tech-news community site Lobsters has retired MariaDB in favour of SQLite after an eight-year migration effort — a small architectural decision with a useful security lesson about trading network attack surface for single-host risk.
devsecopsattack-surfacearchitecture
4 min readRead