Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107314— pgjdbc does not enforce requireAuth when the value excludes every authentication method

Quick assessment

Affected
pgjdbc pgjdbc
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

pgjdbc(PostgreSQL JDBC 驱动程序)在版本 42.7.11 至 42.7.13 中存在安全漏洞。当配置 连接属性以排除驱动程序所知的所有六种认证方法时(例如: ),驱动程序未施加任何限制。此时,驱动程序将接受服务器请求的任何认证方法,包括明文密码认证。此外,不包含任何认证方法值的配置(如 或单个逗号 )也会受到相同影响。 处于应用程序与数据库服务器之间的攻击者可以强制要求使用明文密码认证,并窃取数据库密码。而使用正向白名单方式(如 )或部分排除方式(如 )的 属性值则会按预期正确生效。 该 属性

CVSS 5.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107314

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
pgjdbc does not enforce requireAuth when the value excludes every authentication method
Source: CVE Program / CVE List V5
Vulnerability Description
pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
未能安全地进行程序失效(Failing Open)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
pgjdbc pgjdbc 42.7.11 ~ 42.7.14 -

II. Public POCs for CVE-2026-107314

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107314

请登录查看更多情报信息。

Other References for CVE-2026-107314 (1)

Same Patch Batch · pgjdbc · 2026-10-07 · 3 CVEs total

CVE-2026-107315 5.3 MEDIUM pgjdbc pads a value shorter than its declared length with bytes of earlier statements (rat
CVE-2026-107313 4.2 MEDIUM pgjdbc stores bytes of earlier messages in place of a large value on GSS-encrypted connect

IV. Related Vulnerabilities

V. Comments for CVE-2026-107314

No comments yet


Leave a comment