PostgreSQL JDBC Driver Vulnerability in pgjdbc Affects Multiple Versions
CVE-2026-107314

5.9MEDIUM

Key Information:

Vendor

Pgjdbc

Status
Vendor
CVE Published:
7 October 2026

What is CVE-2026-107314?

The PostgreSQL JDBC Driver (pgjdbc), specifically versions 42.7.11 through 42.7.13, fails to enforce adequate restrictions when the requireAuth connection property excludes all defined authentication methods. This flaw allows an attacker to exploit the driver by requesting cleartext password authentication, compromising sensitive database credentials. When set incorrectly or left empty, applications could unknowingly accept any method requested by the server, leading to potential data breaches. Version 42.7.14 addresses this vulnerability by enforcing restrictions and properly rejecting invalid configurations.

Affected Version(s)

pgjdbc 42.7.11 < 42.7.14

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Coles
.