← Vulnerability feed

Vulnerability record · CVE-2025-49146 · published 11 June 2025

CVE-2025-49146: Postgresql jdbc driver improper authentication vulnerability

Postgresql · Postgresql Jdbc Driver

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.

5.9 CVSS 3.1 Medium EPSS 0.49% · top 60.6% CWE-287 · Improper authentication
5.9CVSS 3.1 base score
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-49146 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-1597Postgresql jdbc driver sql injection vulnerabilitypgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode …EPSS 4.8%9.8CVE-2022-26520Postgresql jdbc driver vulnerabilityIn pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files thr…EPSS 3.0%9.8CVE-2022-21724Postgresql jdbc driver vulnerabilitypgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The…EPSS 3.1%8.2CVE-2026-54291Postgresql jdbc driver vulnerabilitypgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded fr…EPSS 0.24%8.1CVE-2018-10936Postgresql jdbc driver vulnerabilityA weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name v…EPSS 2.9%8.0CVE-2022-31197Postgresql jdbc driver sql injection vulnerabilityPostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. Th…EPSS 2.2%7.7CVE-2020-13692Postgresql jdbc driver xml external entity (xxe) vulnerabilityPostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.EPSS 4.1%7.5CVE-2026-42198Postgresql jdbc driver allocation without limits vulnerabilitypgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of servi…EPSS 4.1%

Source: NIST National Vulnerability Database (record CVE-2025-49146), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.