CVE-2026-107314: pgjdbc does not enforce requireAuth when the value excludes every authentication method
pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pgjdbcto a version that resolves this vulnerability.Fixed in 42.7.14 - Configuration
Replace requireAuth values that exclude every authentication method or name none, including empty or comma-only values, with a positive list of authentication methods used by the server, such as requireAuth=scram-sha-256.
pgjdbc requireAuth = scram-sha-256
Event History
Frequently Asked Questions
Which deployments are exposed?
Only deployments using pgjdbc versions 42.7.11 through 42.7.13 that explicitly set requireAuth to exclude all authentication methods, or set it to a value containing no method such as a single comma, are affected. Deployments that do not set requireAuth are not affected because the property has no default value.
What does an attacker need to exploit this?
An attacker must be positioned between the application and its PostgreSQL server and able to influence the authentication method requested by the server. They can request cleartext password authentication and obtain the database password.
Are any requireAuth configurations safe on affected versions?
Yes. Positive lists such as requireAuth=scram-sha-256 and partial exclusions such as requireAuth=!password,!md5 are enforced correctly.
What is the remediation and how does the fixed version behave?
Upgrade to pgjdbc 42.7.14. In that version, connections using an all-method exclusion are refused with SQLState 08004, and requireAuth values that contain no method are rejected as invalid.