CVE-2026-107314

Source
https://cve.org/CVERecord?id=CVE-2026-107314
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107314.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107314
Aliases
  • GHSA-rhp9-mr79-r74h
Downstream
Published
2026-10-07T23:03:01Z
Modified
2026-10-09T02:49:21Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
pgjdbc does not enforce requireAuth when the value excludes every authentication method
Details

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid.

Database specific
{
    "cna_assigner": "PostgreSQL",
    "cwe_ids": [
        "CWE-636"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107314.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "42.7.11"
                },
                {
                    "fixed": "42.7.14"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/pgjdbc/pgjdbc

Affected ranges

Type
GIT
Repo
https://github.com/pgjdbc/pgjdbc
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "42.7.11"
        },
        {
            "fixed": "42.7.13"
        }
    ],
    "source": "DESCRIPTION"
}

Affected versions

REL42.*
REL42.7.11

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107314.json"