Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Daniel Coles

#48341of 57,635
5.9Total CVSS
Vulnerabilities · 1
PT-2026-107717
5.9
2026-10-07
Pgjdbc · Pgjdbc · CVE-2026-107314
**Name of the Vulnerable Software and Affected Versions** pgjdbc versions 42.7.11 through 42.7.13 **Description** The PostgreSQL JDBC Driver fails to enforce restrictions when the `requireAuth` connection property excludes all six known authentication methods (e.g., `requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none`) or when the property is set to an empty value or a single comma. In these cases, the driver accepts any authentication method requested by the server, including cleartext password authentication. This allows an attacker positioned between the application and the server to request cleartext authentication and obtain the database password. **Recommendations** Update to version 42.7.14. Avoid using the `requireAuth` property with a value that excludes all authentication methods or is left empty.