{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-107314", "assignerOrgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007", "state": "PUBLISHED", "assignerShortName": "PostgreSQL", "dateReserved": "2026-10-07T16:53:39.434Z", "datePublished": "2026-10-07T23:03:01.500Z", "dateUpdated": "2026-10-07T23:03:01.500Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "f86ef6dc-4d3a-42ad-8f28-e6d5547a5007", "shortName": "PostgreSQL", "dateUpdated": "2026-10-07T23:03:01.500Z" }, "title": "pgjdbc does not enforce requireAuth when the value excludes every authentication method", "descriptions": [ { "lang": "en", "value": "pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid." } ], "affected": [ { "vendor": "pgjdbc", "product": "pgjdbc", "collectionURL": "https://repo.maven.apache.org/maven2", "packageName": "org.postgresql:postgresql", "repo": "https://github.com/pgjdbc/pgjdbc", "programFiles": [ "pgjdbc/src/main/java/org/postgresql/core/AuthMethod.java" ], "programRoutines": [ { "name": "org.postgresql.core.AuthMethod.parseRequireAuth" }, { "name": "org.postgresql.core.AuthMethod.checkAuth" } ], "defaultStatus": "unaffected", "versions": [ { "version": "42.7.11", "lessThan": "42.7.14", "status": "affected", "versionType": "maven" } ] } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "type": "CWE", "cweId": "CWE-636", "description": "CWE-636 Not Failing Securely ('Failing Open')" } ] } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.9, "baseSeverity": "MEDIUM" } } ], "solutions": [ { "lang": "en", "value": "Upgrade to pgjdbc 42.7.14 or later, and replace a requireAuth value that excludes every method or names none with a positive list of the methods the server uses." } ], "workarounds": [ { "lang": "en", "value": "Replace the requireAuth value with a positive list of the methods the server uses, for example requireAuth=scram-sha-256; a positive list is enforced correctly on every affected version. A deployment that uses SCRAM over TLS can also set channelBinding=require, which refuses every authentication request other than SCRAM. Verifying the server certificate with sslmode=verify-full against a trusted CA prevents an attacker from presenting a substitute server." } ], "credits": [ { "lang": "en", "type": "reporter", "value": "Daniel Coles" } ], "references": [ { "url": "https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-rhp9-mr79-r74h", "tags": [ "vendor-advisory" ] } ] } } }