CVE-2026-107314: pgjdbc does not enforce requireAuth when the value excludes every authentication method

Published Oct 7, 2026
·
Updated

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid.

Affected Software

1 affected component
PostgreSQL PostgreSQL JDBC driver>=42.7.11<=42.7.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pgjdbc to a version that resolves this vulnerability.

    Fixed in 42.7.14
  2. Configuration

    Replace requireAuth values that exclude every authentication method or name none, including empty or comma-only values, with a positive list of authentication methods used by the server, such as requireAuth=scram-sha-256.

    pgjdbc requireAuth = scram-sha-256

Event History

Oct 7, 2026
CVE Published
via MITRE·11:03 PM
Data Sourced
via MITRE·11:03 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·11:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Only deployments using pgjdbc versions 42.7.11 through 42.7.13 that explicitly set requireAuth to exclude all authentication methods, or set it to a value containing no method such as a single comma, are affected. Deployments that do not set requireAuth are not affected because the property has no default value.

2

What does an attacker need to exploit this?

An attacker must be positioned between the application and its PostgreSQL server and able to influence the authentication method requested by the server. They can request cleartext password authentication and obtain the database password.

3

Are any requireAuth configurations safe on affected versions?

Yes. Positive lists such as requireAuth=scram-sha-256 and partial exclusions such as requireAuth=!password,!md5 are enforced correctly.

4

What is the remediation and how does the fixed version behave?

Upgrade to pgjdbc 42.7.14. In that version, connections using an all-method exclusion are refused with SQLState 08004, and requireAuth values that contain no method are rejected as invalid.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203