Improper Message Integrity Enforcement in PostgreSQL GSSAPI Support
CVE-2026-14681

4.2MEDIUM

Key Information:

Vendor

PostgreSQL

Vendor
CVE Published:
13 August 2026

What is CVE-2026-14681?

This vulnerability pertains to a flaw in the GSSAPI implementation of PostgreSQL. It allows users to negotiate GSSAPI support contrary to the defined rules in the pg_hba.conf file, potentially undermining the expected security controls. When a direct TLS connection is established, it may permit data exchanges over TLS alone, thereby circumventing stricter GSSAPI requirements. As a result, if the TLS configurations are more lenient compared to those for GSSAPI, this may lead to weakened data protection. This affects major versions 17 and 18 of PostgreSQL but excludes versions prior to 17.

Affected Version(s)

PostgreSQL 18 < 18.5

PostgreSQL 17 < 17.11

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

The PostgreSQL project thanks p4p3r for reporting this problem.
.