Blog
Insights on software development, security, and technology from our team.

A PostgreSQL backup account can now run code on your server. Patch CVE-2026-6471.
PostgreSQL patched CVE-2026-6471, a flaw present since 2014 that lets a low-privilege REPLICATION account load arbitrary code and take over the database host. The official severity is 7.2, not critical, because it needs an account that backup tools, replicas and CDC pipelines all use. Here is how to patch, what the new output_plugin_libraries allowlist changes, and which service accounts to audit first.
SQLite carried a corruption bug for 16 years. Here's why yours is probably fine, and what to check anyway.
Tailscale spent six months chasing database corruption that turned out to be a 16-year-old data race in SQLite's WAL mode. The fix landed in SQLite 3.51.3, but the real work for most teams is finding out which SQLite version they actually run and proving their backups restore clean. Here's what we'd do about it.
Redis 8.8 finally has native arrays and a built-in rate limiter. Here's what to do with them.
Redis 8.8 just shipped with a native array data type and INCREX, a built-in rate-limiting command that replaces the hand-rolled Lua most teams run today. The features are genuinely useful, but the smart move isn't to upgrade on Friday. Here's how we'd approach it for a client, and the one audit worth doing this week regardless.