Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107315— pgjdbc pads a value shorter than its declared length with bytes of earlier statements (rather than zeros)

Quick assessment

Affected
pgjdbc pgjdbc
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

pgjdbc(PostgreSQL JDBC 驱动)在版本 42.7.4 至 42.7.13 中存在一个漏洞:当写入的值短于其声明长度时,驱动会使用发送缓冲区中剩余的字节(而非零字节)进行填充,并将这些字节作为值的一部分存储到服务器中。这些残留字节是驱动在同一连接上先前发送的消息内容,包括 SQL 文本和最近语句的参数值;在连接池场景下,这些数据可能来自其他用户的请求。每个被填充的值最多可携带 8192 字节的此类敏感信息;若连接启用了 GSS 加密,则可携带多达 16320 字节。 该填充行为发生在应用程序声明的

CVSS 5.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107315

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
pgjdbc pads a value shorter than its declared length with bytes of earlier statements (rather than zeros)
Source: CVE Program / CVE List V5
Vulnerability Description
pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.13 pads a value that is shorter than its declared length with bytes left in its send buffer instead of zeros, and the server stores those bytes as part of the value. The bytes are messages the driver sent earlier on the same connection: SQL text and parameter values of recent statements, which on a pooled connection can come from other requests. Each padded value can carry up to 8192 bytes of this traffic, or 16320 bytes on a connection with GSS encryption. The padding happens when an application declares a length larger than the data it supplies, through PreparedStatement.setObject with a ByteStreamWriter, CopyIn.writeToCopy, PGCopyOutputStream.write, LargeObject.write, or Blob.setBytes. The driver accepts these calls without an error. An attacker who can make the application store such a value and read it back can collect earlier traffic. Applications whose declared lengths always match their data are not affected. Versions 42.7.3 and earlier pad with zeros.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在释放前未清除敏感信息
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
pgjdbc pgjdbc 42.7.4 ~ 42.7.13 -

II. Public POCs for CVE-2026-107315

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107315

请登录查看更多情报信息。

Other References for CVE-2026-107315 (1)

Same Patch Batch · pgjdbc · 2026-10-07 · 3 CVEs total

CVE-2026-107314 5.9 MEDIUM pgjdbc does not enforce requireAuth when the value excludes every authentication method
CVE-2026-107313 4.2 MEDIUM pgjdbc stores bytes of earlier messages in place of a large value on GSS-encrypted connect

IV. Related Vulnerabilities

V. Comments for CVE-2026-107315

No comments yet


Leave a comment