Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to pgjdbc 42.7.14 or later, and replace a requireAuth value that excludes every method or names none with a positive list of the methods the server uses.
Vendor Workaround
Replace the requireAuth value with a positive list of the methods the server uses, for example requireAuth=scram-sha-256; a positive list is enforced correctly on every affected version. A deployment that uses SCRAM over TLS can also set channelBinding=require, which refuses every authentication request other than SCRAM. Verifying the server certificate with sslmode=verify-full against a trusted CA prevents an attacker from presenting a substitute server.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pgjdbc
Pgjdbc pgjdbc |
|
| Vendors & Products |
Pgjdbc
Pgjdbc pgjdbc |
Wed, 07 Oct 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid. | |
| Title | pgjdbc does not enforce requireAuth when the value excludes every authentication method | |
| Weaknesses | CWE-636 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-10-08T14:47:31.949Z
Reserved: 2026-10-07T16:53:39.434Z
Link: CVE-2026-107314
Updated: 2026-10-08T14:47:13.036Z
Status : Received
Published: 2026-10-07T23:17:00.337
Modified: 2026-10-08T15:17:42.483
Link: CVE-2026-107314
No data.
OpenCVE Enrichment
Updated: 2026-10-08T00:30:04Z