RHSA-2026:52978: Important: postgresql-jdbc security update
Important: postgresql-jdbc security update
Other sources
PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.Security Fix(es): jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication (CVE-2026-42198) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/postgresql-jdbcto a version that resolves this vulnerability.Fixed in 42.2.14-5.el8_8.1 - Upgrade
Upgrade
redhat/postgresql-jdbc-javadocto a version that resolves this vulnerability.Fixed in 42.2.14-5.el8_8.1 - Compensating control
Mitigate client-side DoS from pgjdbc (CVE-2026-42198) by restricting which clients/systems can connect to the PostgreSQL endpoints that use SCRAM-SHA-256 authentication, e.g., via network ACL/firewall rules allowing only trusted source IPs.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:52978?
The severity of RHSA-2026:52978 is classified as high with a score of 7.
How do I fix RHSA-2026:52978?
To fix RHSA-2026:52978, you need to apply the available postgresql-jdbc security update through your package manager.
What vulnerabilities does RHSA-2026:52978 address?
RHSA-2026:52978 addresses security vulnerabilities in postgresql-jdbc that could lead to unauthorized access or data breaches.
Which products are affected by RHSA-2026:52978?
RHSA-2026:52978 affects Red Hat Enterprise Linux Server for Power LE, x86_64, and Update Services for SAP Solutions.
When was RHSA-2026:52978 published?
RHSA-2026:52978 was published on August 10, 2026.