HIGH🇵🇱 Wersja polska

CVE-2025-49146

CVSS 8.2v3.1pub. 2025-06-11upd. 2025-10-06

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
  • PostgreSQL Jdbc Driver

    APP
    Postgresql
    42.7.4 – 42.7.7 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-1597CRITICAL10.0PL ✓same product

SQL Injection w PostgreSQL JDBC Driver (pgjdbc) — tryb SIMPLE

CVE-2022-26520CRITICAL9.8PL ✓same product

Zapis do dowolnych plików przez pgjdbc via loggerFile (przed 42.3.3)

CVE-2026-54291HIGH8.2PL ✓same product

Cicha degradacja channel binding w PostgreSQL JDBC Driver (pgjdbc)

CVE-2026-42198HIGH7.5same product

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vuln...

CVE-2022-31197HIGH7.1same product

PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using stand...