Description
pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid.
Published: 2026-10-07
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade to pgjdbc 42.7.14 or later, and replace a requireAuth value that excludes every method or names none with a positive list of the methods the server uses.


Vendor Workaround

Replace the requireAuth value with a positive list of the methods the server uses, for example requireAuth=scram-sha-256; a positive list is enforced correctly on every affected version. A deployment that uses SCRAM over TLS can also set channelBinding=require, which refuses every authentication request other than SCRAM. Verifying the server certificate with sslmode=verify-full against a trusted CA prevents an attacker from presenting a substitute server.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Pgjdbc
Pgjdbc pgjdbc
Vendors & Products Pgjdbc
Pgjdbc pgjdbc

Wed, 07 Oct 2026 23:15:00 +0000

Type Values Removed Values Added
Description pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid.
Title pgjdbc does not enforce requireAuth when the value excludes every authentication method
Weaknesses CWE-636
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: PostgreSQL

Published:

Updated: 2026-10-07T23:03:01.500Z

Reserved: 2026-10-07T16:53:39.434Z

Link: CVE-2026-107314

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T23:17:00.337

Modified: 2026-10-07T23:17:00.337

Link: CVE-2026-107314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T00:30:04Z

Weaknesses
  • CWE-636

    Not Failing Securely ('Failing Open')