{"api_version":"1","generated_at":"2026-10-08T03:06:01+00:00","cve":"CVE-2026-107314","urls":{"html":"https://cve.report/CVE-2026-107314","api":"https://cve.report/api/cve/CVE-2026-107314.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-107314","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-107314"},"summary":{"title":"pgjdbc does not enforce requireAuth when the value excludes every authentication method","description":"pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid.","state":"PUBLISHED","assigner":"PostgreSQL","published_at":"2026-10-07 23:17:00","updated_at":"2026-10-07 23:17:00"},"problem_types":["CWE-636","CWE-636 CWE-636 Not Failing Securely ('Failing Open')"],"metrics":[{"version":"3.1","source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","type":"Secondary","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-rhp9-mr79-r74h","name":"https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-rhp9-mr79-r74h","refsource":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-107314","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107314","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"pgjdbc","product":"pgjdbc","version":"affected 42.7.11 42.7.14 maven","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Upgrade to pgjdbc 42.7.14 or later, and replace a requireAuth value that excludes every method or names none with a positive list of the methods the server uses.","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"Replace the requireAuth value with a positive list of the methods the server uses, for example requireAuth=scram-sha-256; a positive list is enforced correctly on every affected version. A deployment that uses SCRAM over TLS can also set channelBinding=require, which refuses every authentication request other than SCRAM. Verifying the server certificate with sslmode=verify-full against a trusted CA prevents an attacker from presenting a substitute server.","time":"","lang":"en"}],"exploits":[],"credits":[{"source":"CNA","value":"Daniel Coles","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://repo.maven.apache.org/maven2","defaultStatus":"unaffected","packageName":"org.postgresql:postgresql","product":"pgjdbc","programFiles":["pgjdbc/src/main/java/org/postgresql/core/AuthMethod.java"],"programRoutines":[{"name":"org.postgresql.core.AuthMethod.parseRequireAuth"},{"name":"org.postgresql.core.AuthMethod.checkAuth"}],"repo":"https://github.com/pgjdbc/pgjdbc","vendor":"pgjdbc","versions":[{"lessThan":"42.7.14","status":"affected","version":"42.7.11","versionType":"maven"}]}],"credits":[{"lang":"en","type":"reporter","value":"Daniel Coles"}],"descriptions":[{"lang":"en","value":"pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid."}],"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-636","description":"CWE-636 Not Failing Securely ('Failing Open')","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-07T23:03:01.500Z","orgId":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","shortName":"PostgreSQL"},"references":[{"tags":["vendor-advisory"],"url":"https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-rhp9-mr79-r74h"}],"solutions":[{"lang":"en","value":"Upgrade to pgjdbc 42.7.14 or later, and replace a requireAuth value that excludes every method or names none with a positive list of the methods the server uses."}],"title":"pgjdbc does not enforce requireAuth when the value excludes every authentication method","workarounds":[{"lang":"en","value":"Replace the requireAuth value with a positive list of the methods the server uses, for example requireAuth=scram-sha-256; a positive list is enforced correctly on every affected version. A deployment that uses SCRAM over TLS can also set channelBinding=require, which refuses every authentication request other than SCRAM. Verifying the server certificate with sslmode=verify-full against a trusted CA prevents an attacker from presenting a substitute server."}]}},"cveMetadata":{"assignerOrgId":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","assignerShortName":"PostgreSQL","cveId":"CVE-2026-107314","datePublished":"2026-10-07T23:03:01.500Z","dateReserved":"2026-10-07T16:53:39.434Z","dateUpdated":"2026-10-07T23:03:01.500Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-07 23:17:00","lastModifiedDate":"2026-10-07 23:17:00","problem_types":["CWE-636","CWE-636 CWE-636 Not Failing Securely ('Failing Open')"],"metrics":{"cvssMetricV31":[{"source":"f86ef6dc-4d3a-42ad-8f28-e6d5547a5007","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"107314","Ordinal":"1","Title":"pgjdbc does not enforce requireAuth when the value excludes ever","CVE":"CVE-2026-107314","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"107314","Ordinal":"1","NoteData":"pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13 enforce no restriction when the requireAuth connection property excludes all six authentication methods the driver knows, for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver then accepts any method the server asks for, including cleartext password authentication. A value without a method in it, such as requireAuth=, (a single comma), is affected the same way. An attacker positioned between the application and its server can ask for cleartext password authentication and receive the database password. A positive list such as requireAuth=scram-sha-256, and a partial exclusion such as requireAuth=!password,!md5, are enforced correctly. The property has no default value, so a deployment that does not set it is not affected. 42.7.14 fixes the problem: such a connection is refused with SQLState 08004, and a value without a method in it is rejected as invalid.","Type":"Description","Title":"pgjdbc does not enforce requireAuth when the value excludes ever"}]}}}