CVE-2026-107313
Received Received - Intake

Information Leakage in pgjdbc PostgreSQL JDBC Driver

Vulnerability report for CVE-2026-107313, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: PostgreSQL

Description

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 and 42.7.5 can send the previous contents of the GSS send buffer in place of the first part of a value on a connection with GSS encryption (gssEncMode=prefer or require), and the server stores the value without an error. The buffer is 16320 bytes with MIT Kerberos. The stored value then holds bytes of the messages the driver sent just before it on the same connection, such as the statement's SQL text, its other parameters, and earlier rows of the same batch, instead of the bytes the application supplied. Values at least as long as the buffer are affected when the driver writes them from a byte array: bind parameters set with setString, setBytes, or a ByteStreamWriter, CopyIn.writeToCopy, and LargeObject.write. Most such writes fail with an ArrayIndexOutOfBoundsException instead. The default, gssEncMode=allow, does not start GSS encryption, and connections without GSS encryption are not affected. Versions 42.7.3 and earlier are not affected, and 42.7.6 fixes the problem.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-08
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pgjdbc pgjdbc 42.7.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the PostgreSQL JDBC Driver (pgjdbc) versions 42.7.4 and 42.7.5 when using GSS encryption. When writing large values (16320+ bytes), the driver incorrectly sends the previous contents of the GSS send buffer instead of the intended data. This causes the server to store incorrect information, including parts of earlier messages like SQL text or parameters.

Detection Guidance

To detect this vulnerability, check the pgjdbc driver version in use. Run commands like 'mvn dependency:tree' for Maven projects or inspect dependency files to identify if version 42.7.4 or 42.7.5 is present. Verify if GSS encryption is enabled by checking connection strings or configurations for 'gssEncMode=prefer' or 'gssEncMode=require'.

Impact Analysis

The impact includes data corruption where sensitive information from prior messages may be stored instead of the intended data. This could lead to incorrect database records, potential security breaches if sensitive data is exposed, and application crashes due to ArrayIndexOutOfBoundsException when handling large objects.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by exposing sensitive data through incorrect data storage. If personal or health information is stored improperly due to this flaw, it may violate data integrity and confidentiality requirements mandated by these regulations.

Mitigation Strategies

Upgrade the pgjdbc driver to version 42.7.6 or later immediately. If upgrading is not possible, disable GSS encryption by setting 'gssEncMode=allow' or removing GSS encryption settings from connection configurations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107313. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart