Man-in-the-Middle Vulnerability in PostgreSQL JDBC Driver by pgjdbc
CVE-2025-49146
8.2HIGH
What is CVE-2025-49146?
The PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.7, allows man-in-the-middle attackers to intercept confidential connections by incorrectly permitting authentication methods that do not support channel binding. When configured with channel binding set to required, the driver fails to enforce this requirement during the authentication process, creating a serious security risk. This vulnerability can lead to unauthorized access to sensitive data. Upgrading to version 42.7.7 or later is imperative for users to mitigate this risk.
Affected Version(s)
pgjdbc >= 42.7.4, < 42.7.7