Key details

  1. Security release: pgJDBC 42.7.14, October 7, 2026.
  2. CVE-2026-107314 affects 42.7.11–42.7.13 with invalid or deny-all requireAuth rules.
  3. CVE-2026-107315 affects 42.7.4–42.7.13 when actual binary bytes are shorter than the declared length.
  4. The fix can change invalid requireAuth configurations from connecting to failing closed.
  5. Potential leaked content includes earlier SQL statements and parameters from the same connection.

What builders should take away

  1. Upgrade PostgreSQL JDBC dependencies to 42.7.14 and check transitive copies.
  2. Audit requireAuth values and use explicit positive authentication lists.
  3. Review ByteStreamWriter, COPY, Blob and large-object code for accurate byte lengths.
  4. Scope incident exposure to affected driver versions and the documented triggers.

What changed

On October 7, 2026 the PostgreSQL JDBC maintainers released 42.7.14. CVE-2026-107314 affects versions 42.7.11–42.7.13: when requireAuth excludes every authentication method or is invalid, the driver silently ignores the restriction and can accept cleartext password authentication. CVE-2026-107315 affects 42.7.4–42.7.13: if callers write fewer bytes than a declared length, padding can contain previous messages from the connection, including SQL text and parameter values, rather than zeroes. Both flaws are fixed in 42.7.14.

Why it matters

A client driver can leak credentials or data across requests even if the PostgreSQL server itself is not vulnerable. A malicious server or intermediary could exploit a fail-open authentication restriction. Short binary writes on a pooled connection could persist earlier request data for a later reader. These are conditional risks, not universal failures: valid requireAuth rules and correctly sized writes do not trigger the described bugs.

Invalid deny-all authentication rules could fail open

Versions 42.7.11–42.7.13 treated a requireAuth value excluding all supported methods as if it were absent. That could allow a server-requested weaker method, including cleartext password. In 42.7.14 the connection fails instead. Positive allowlists and partial exclusions were not affected.

Earlier SQL data could appear in stored binary values

Versions 42.7.4–42.7.13 used previous send-buffer contents to pad short binary writes. Affected ByteStreamWriter, COPY and large-object paths can put previous statements and parameters into stored data, especially on pooled connections. The vulnerability record describes up to 8,192 bytes, or 16,320 with GSS encryption, under relevant conditions.

The security upgrade may expose invalid configuration

42.7.14 refuses invalid deny-all requireAuth settings, so deployments relying on the former fail-open behavior can stop connecting. Replace invalid expressions with a positive list of the authentication methods actually used and test against production-like servers.

The trigger conditions narrow the affected population

An application not setting requireAuth is not exposed to the first issue; applications with matching declared and actual binary lengths are not exposed to the second. This is a JDBC-driver security update, not a PostgreSQL database-server upgrade.

What to watch next

  • Downstream ORM/framework and distribution packaging of the fixed driver.
  • Further advisories or evidence of exploitation.
  • Regression tests for connection-pool buffer handling.

Still unclear

  • Real exposure depends on application-specific configuration and write patterns.
  • The cited sources do not establish widespread exploitation.
  • Readback access is needed to exploit persisted padding data.

Sources

Direct reading behind this dossier.

4 sources
CVE-2026-107314
Tenable independent

Authentication downgrade scope.

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment