← Vulnerability feed

Vulnerability record · CVE-2026-54291 · published 6 July 2026

CVE-2026-54291: Postgresql jdbc driver vulnerability

Postgresql · Postgresql Jdbc Driver

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.

8.2 CVSS 4.0 High EPSS 0.24% · top 86.8% CWE-636 · CWE-636CWE-757 · CWE-757
8.2CVSS 4.0 base score
0.24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
9 Jul 2026Last modified by NVD

Description

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-54291 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-1597Postgresql jdbc driver sql injection vulnerabilitypgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode …EPSS 4.8%9.8CVE-2022-26520Postgresql jdbc driver vulnerabilityIn pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files thr…EPSS 3.0%9.8CVE-2022-21724Postgresql jdbc driver vulnerabilitypgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The…EPSS 3.1%8.1CVE-2018-10936Postgresql jdbc driver vulnerabilityA weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name v…EPSS 2.9%8.0CVE-2022-31197Postgresql jdbc driver sql injection vulnerabilityPostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. Th…EPSS 2.1%7.7CVE-2020-13692Postgresql jdbc driver xml external entity (xxe) vulnerabilityPostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.EPSS 4.1%7.5CVE-2026-42198Postgresql jdbc driver allocation without limits vulnerabilitypgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of servi…EPSS 4.1%7.5CVE-2012-1618Postgresql vulnerabilityInteraction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled,…EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2026-54291), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.