pgjdbc(PostgreSQL JDBC 驱动)在版本 42.7.4 至 42.7.13 中存在一个漏洞:当写入的值短于其声明长度时,驱动会使用发送缓冲区中剩余的字节(而非零字节)进行填充,并将这些字节作为值的一部分存储到服务器中。这些残留字节是驱动在同一连接上先前发送的消息内容,包括 SQL 文本和最近语句的参数值;在连接池场景下,这些数据可能来自其他用户的请求。每个被填充的值最多可携带 8192 字节的此类敏感信息;若连接启用了 GSS 加密,则可携带多达 16320 字节。 该填充行为发生在应用程序声明的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107314 | 5.9 MEDIUM | pgjdbc does not enforce requireAuth when the value excludes every authentication method |
| CVE-2026-107313 | 4.2 MEDIUM | pgjdbc stores bytes of earlier messages in place of a large value on GSS-encrypted connect |
No comments yet