# PostgreSQL JDBC 42.7.14 closes authentication and SQL-data leakage flaws

pgJDBC 42.7.14 fixes two security failures: a deny-all authentication setting that silently failed open and a short-write buffer bug that could store previous SQL and parameter bytes in database fields.

Two pgJDBC vulnerabilities affect different older driver ranges and only specific connection or binary-write configurations. Upgrade and verify the affected paths rather than treating this as a PostgreSQL server vulnerability.

- Status: Active
- Published: 2026-10-10T09:45:50+13:00
- Updated: 2026-10-10T09:45:50+13:00
- Categories: Web Development, Cloud & Infrastructure, Developer Tools, Databases & Storage
- Tags: data exposure, JDBC, pgJDBC, PostgreSQL, security
- Canonical HTML: https://beyondthe.news/dossiers/postgresql-jdbc-42-7-14-requireauth-buffer-leak-security-cves

## What changed

On October 7, 2026 the PostgreSQL JDBC maintainers released 42.7.14. CVE-2026-107314 affects versions 42.7.11–42.7.13: when requireAuth excludes every authentication method or is invalid, the driver silently ignores the restriction and can accept cleartext password authentication. CVE-2026-107315 affects 42.7.4–42.7.13: if callers write fewer bytes than a declared length, padding can contain previous messages from the connection, including SQL text and parameter values, rather than zeroes. Both flaws are fixed in 42.7.14.

## Why it matters

A client driver can leak credentials or data across requests even if the PostgreSQL server itself is not vulnerable. A malicious server or intermediary could exploit a fail-open authentication restriction. Short binary writes on a pooled connection could persist earlier request data for a later reader. These are conditional risks, not universal failures: valid requireAuth rules and correctly sized writes do not trigger the described bugs.

## Invalid deny-all authentication rules could fail open

Versions 42.7.11–42.7.13 treated a requireAuth value excluding all supported methods as if it were absent. That could allow a server-requested weaker method, including cleartext password. In 42.7.14 the connection fails instead. Positive allowlists and partial exclusions were not affected.

## Earlier SQL data could appear in stored binary values

Versions 42.7.4–42.7.13 used previous send-buffer contents to pad short binary writes. Affected ByteStreamWriter, COPY and large-object paths can put previous statements and parameters into stored data, especially on pooled connections. The vulnerability record describes up to 8,192 bytes, or 16,320 with GSS encryption, under relevant conditions.

## The security upgrade may expose invalid configuration

42.7.14 refuses invalid deny-all requireAuth settings, so deployments relying on the former fail-open behavior can stop connecting. Replace invalid expressions with a positive list of the authentication methods actually used and test against production-like servers.

## The trigger conditions narrow the affected population

An application not setting requireAuth is not exposed to the first issue; applications with matching declared and actual binary lengths are not exposed to the second. This is a JDBC-driver security update, not a PostgreSQL database-server upgrade.

## Key details

- Security release: pgJDBC 42.7.14, October 7, 2026.
- CVE-2026-107314 affects 42.7.11–42.7.13 with invalid or deny-all requireAuth rules.
- CVE-2026-107315 affects 42.7.4–42.7.13 when actual binary bytes are shorter than the declared length.
- The fix can change invalid requireAuth configurations from connecting to failing closed.
- Potential leaked content includes earlier SQL statements and parameters from the same connection.

## Builder takeaways

- Upgrade PostgreSQL JDBC dependencies to 42.7.14 and check transitive copies.
- Audit requireAuth values and use explicit positive authentication lists.
- Review ByteStreamWriter, COPY, Blob and large-object code for accurate byte lengths.
- Scope incident exposure to affected driver versions and the documented triggers.

## What to watch

- Downstream ORM/framework and distribution packaging of the fixed driver.
- Further advisories or evidence of exploitation.
- Regression tests for connection-pool buffer handling.

## Uncertainties

- Real exposure depends on application-specific configuration and write patterns.
- The cited sources do not establish widespread exploitation.
- Readback access is needed to exploit persisted padding data.

## Sources

- [PostgreSQL JDBC Driver 42.7.14 Released](https://jdbc.postgresql.org/changelogs/2026-10-07-42.7.14-release/) — pgJDBC · primary · 2026-10-07T00:00:00+13:00. Maintainer's version ranges and fixed behavior.
- [PostgreSQL JDBC security update](https://www.postgresql.org/about/news/2026-10-07-postgresql-jdbc-42714-security-update-for-multiple-cves-3399/) — PostgreSQL Global Development Group · primary · 2026-10-09T00:00:00+13:00. Confirms both CVEs.
- [CVE-2026-107315 vulnerability record](https://db.gcve.eu/vuln/cve-2026-107315) — Vulnerability-Lookup · independent · 2026-10-08T00:00:00+13:00. Technical leakage conditions.
- [CVE-2026-107314](https://www.tenable.com/cve/CVE-2026-107314) — Tenable · independent · 2026-10-07T00:00:00+13:00. Authentication downgrade scope.

