PatchSiren

pgjdbc CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH pgjdbc CVE published 2026-07-06

CVE-2026-54291

The CVE-2026-54291 vulnerability in pgjdbc, a PostgreSQL JDBC driver, allows for a silent downgrade of SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it. This downgrade can be triggered by an attacker who can intercept the TLS connection with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash. The issue arises because the bundled com.ongres.scr [truncated]

HIGH pgjdbc CVE published 2026-04-29

CVE-2026-42198

A vulnerability in pgjdbc, a PostgreSQL JDBC driver, can cause a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a large iteration count, leading to high CPU usage and potential exhaustion of client CPU resources. This issue affects versions 42.2.0 to before 42.7.11 of pgjdbc. Defenders should assess exposur [truncated]