PT-2026-71477 · Postgresql Global Development Group+2 · Postgresql+2

CVE-2026-14681

·

Published

2026-08-12

·

Updated

2026-09-03

CVSS v2.0

4.6

Medium

VectorAV:N/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostgreSQL versions 17.0 through 17.10 PostgreSQL versions 18.0 through 18.4
Description Improper enforcement of message integrity in GSSAPI support allows a user to negotiate GSSAPI in a manner that contradicts pg hba.conf rules during an initial direct TLS connection. This can result in a connection exchanging data using only TLS encryption, even when pg hba.conf is configured to require GSSAPI. If TLS settings are more permissive than GSS settings, the connection may proceed with a lower level of protection.
Recommendations Update PostgreSQL versions 17.x to 17.11. Update PostgreSQL versions 18.x to 18.5.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11965
BIT-POSTGRESQL-2026-14681
CVE-2026-14681
ECHO-1690-243F-9082
OESA-2026-3423
OESA-2026-3424
OPENSUSE-SU-2026:11555-1
OPENSUSE-SU-2026:11565-1
OPENSUSE-SU-2026:21702-1
OPENSUSE-SU-2026:21703-1
SUSE-SU-2026:3942-1
USN-8653-1

Affected Products

Linuxmint
Postgresql
Ubuntu