PostgreSQL JDBC Driver Vulnerability Affecting GSS Encryption
CVE-2026-107313

4.2MEDIUM

Key Information:

Vendor

Pgjdbc

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107313?

The PostgreSQL JDBC Driver versions 42.7.4 and 42.7.5 have a vulnerability that allows the transmission of the previous contents of the GSS send buffer when using GSS encryption. This issue enables attackers to retrieve sensitive data, including SQL statements and parameters, that were sent prior to the compromised operation. Specifically, when application values are written to the database, this incorrect behavior can lead to unintended data exposure, especially for values that are as long as the 16320 bytes buffer. While connections without GSS encryption remain unaffected, it is critical for users of the impacted driver versions to update to 42.7.6 or later to mitigate this data leakage risk.

Affected Version(s)

pgjdbc 42.7.4 < 42.7.6

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Vladimir Sitnikov
.