What changed
On October 7, 2026 the PostgreSQL JDBC maintainers released 42.7.14. CVE-2026-107314 affects versions 42.7.11–42.7.13: when requireAuth excludes every authentication method or is invalid, the driver silently ignores the restriction and can accept cleartext password authentication. CVE-2026-107315 affects 42.7.4–42.7.13: if callers write fewer bytes than a declared length, padding can contain previous messages from the connection, including SQL text and parameter values, rather than zeroes. Both flaws are fixed in 42.7.14.
Why it matters
A client driver can leak credentials or data across requests even if the PostgreSQL server itself is not vulnerable. A malicious server or intermediary could exploit a fail-open authentication restriction. Short binary writes on a pooled connection could persist earlier request data for a later reader. These are conditional risks, not universal failures: valid requireAuth rules and correctly sized writes do not trigger the described bugs.
Invalid deny-all authentication rules could fail open
Versions 42.7.11–42.7.13 treated a requireAuth value excluding all supported methods as if it were absent. That could allow a server-requested weaker method, including cleartext password. In 42.7.14 the connection fails instead. Positive allowlists and partial exclusions were not affected.
Earlier SQL data could appear in stored binary values
Versions 42.7.4–42.7.13 used previous send-buffer contents to pad short binary writes. Affected ByteStreamWriter, COPY and large-object paths can put previous statements and parameters into stored data, especially on pooled connections. The vulnerability record describes up to 8,192 bytes, or 16,320 with GSS encryption, under relevant conditions.
The security upgrade may expose invalid configuration
42.7.14 refuses invalid deny-all requireAuth settings, so deployments relying on the former fail-open behavior can stop connecting. Replace invalid expressions with a positive list of the authentication methods actually used and test against production-like servers.
The trigger conditions narrow the affected population
An application not setting requireAuth is not exposed to the first issue; applications with matching declared and actual binary lengths are not exposed to the second. This is a JDBC-driver security update, not a PostgreSQL database-server upgrade.