pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A maliciou…
High CVSS 7.5
Summary
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust …
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/pgjdbc/pgjdbc/releases/tag/REL42.7.11 Release Notes
- https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-98qh-xjc8-98pq Vendor Advisory
- https://access.redhat.com/errata/RHSA-2026:19098
- https://access.redhat.com/errata/RHSA-2026:22304
- https://access.redhat.com/errata/RHSA-2026:24348
- https://access.redhat.com/errata/RHSA-2026:25030
- https://access.redhat.com/errata/RHSA-2026:52928
- https://access.redhat.com/errata/RHSA-2026:52929
- https://access.redhat.com/errata/RHSA-2026:52930
- https://access.redhat.com/errata/RHSA-2026:52978
- https://access.redhat.com/security/cve/CVE-2026-42198
- https://bugzilla.redhat.com/show_bug.cgi?id=2463857
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42198.json
Timeline
- nvd_ingest NVD