CVE-2026-107315
Received Received - Intake

Information Leakage in pgjdbc PostgreSQL JDBC Driver

Vulnerability report for CVE-2026-107315, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: PostgreSQL

Description

pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.13 pads a value that is shorter than its declared length with bytes left in its send buffer instead of zeros, and the server stores those bytes as part of the value. The bytes are messages the driver sent earlier on the same connection: SQL text and parameter values of recent statements, which on a pooled connection can come from other requests. Each padded value can carry up to 8192 bytes of this traffic, or 16320 bytes on a connection with GSS encryption. The padding happens when an application declares a length larger than the data it supplies, through PreparedStatement.setObject with a ByteStreamWriter, CopyIn.writeToCopy, PGCopyOutputStream.write, LargeObject.write, or Blob.setBytes. The driver accepts these calls without an error. An attacker who can make the application store such a value and read it back can collect earlier traffic. Applications whose declared lengths always match their data are not affected. Versions 42.7.3 and earlier pad with zeros.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pgjdbc pgjdbc 42.7.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-226 The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in pgjdbc (PostgreSQL JDBC Driver) versions 42.7.4 to 42.7.13 causes the driver to pad values shorter than their declared length with leftover data from its send buffer instead of zeros. This exposes sensitive information like SQL text and parameter values from previous statements on the same connection.

Detection Guidance

This vulnerability cannot be directly detected via network or system commands as it involves application-level data leakage within the PostgreSQL JDBC driver. The issue is internal to the driver's handling of padded values. To mitigate, update the pgjdbc driver to version 42.7.14 or later.

Impact Analysis

An attacker who can manipulate the application into storing and reading back such padded values could collect up to 8192 bytes (16320 with GSS encryption) of prior traffic. This is especially risky for applications using pooled connections where leaked data may come from other requests.

Compliance Impact

This vulnerability could lead to exposure of sensitive data such as SQL queries and parameter values from prior statements on the same connection. This may violate data protection requirements under GDPR and HIPAA, which mandate strict controls over data confidentiality and integrity.

Mitigation Strategies

Upgrade the pgjdbc driver to version 42.7.14 or later to address the vulnerability. Review application code to ensure declared lengths match actual data sizes to avoid padding issues.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107315. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart