Man-in-the-Middle Vulnerability in PostgreSQL JDBC Driver by pgjdbc
CVE-2025-49146
What is CVE-2025-49146?
The PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.7, allows man-in-the-middle attackers to intercept confidential connections by incorrectly permitting authentication methods that do not support channel binding. When configured with channel binding set to required, the driver fails to enforce this requirement during the authentication process, creating a serious security risk. This vulnerability can lead to unauthorized access to sensitive data. Upgrading to version 42.7.7 or later is imperative for users to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
pgjdbc >= 42.7.4, < 42.7.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
