CVE-2026-42198

high
Published 2026-04-29 Β· Modified 2026-06-01
CVSS v3
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
7.5

Description

RHSA-2026:22304: postgresql-jdbc security update (Important)

Predictions

Exploit likelihood
83%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata β€” Red Hat Inc. Β· View original β†— Β· Open-Errata-API

Description jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) Errata / fixed releases ProductPackageAdvisoryReleased Red Hat build of Quarkus 3.27.3.SP2pgjdbcRHSA-2026:190982026-05-20T00:00:00Z Red Hat Enterprise Linux…

Description

jdbc.postgresql.org: pgjdbc: Client-side Denial of Service via malicious SCRAM-SHA-256 authentication

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
Red Hat build of Quarkus 3.27.3.SP2pgjdbcRHSA-2026:190982026-05-20T00:00:00Z
Red Hat Enterprise Linux 9postgresql-jdbc-0:42.2.28-2.el9_8.2RHSA-2026:223042026-06-01T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 10postgresql-jdbcAffected
Red Hat Enterprise Linux 6postgresql-jdbcWill not fix
Red Hat Enterprise Linux 7postgresql-jdbcAffected
Red Hat Enterprise Linux 8postgresql-jdbcAffected

Apply commands

bash fix
Apply RHSA-2026:19098 for Red Hat build of Quarkus 3.27.3.SP2
yum update -y pgjdbc
# or:
dnf upgrade -y pgjdbc

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 7Affected
redhatRed Hat Enterprise Linux 8Affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected β€”
sid Fixed 42.7.11-1
forky Fixed 42.7.11-1
bullseye Affected β€”
bookworm Affected β€”
redhat Red Hat Fixed 1 release
VersionStatusFixed in
9 Fixed β€”

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.postgresql:postgresql>=42.2.0,<42.7.1142.7.11
java MAVENorg.postgresql:postgresql>= 42.2.0, < 42.7.1142.7.11

Application impact

VendorProductVersionsFixed
postgresql postgresqlpostgresql_jdbc_driver{"startIncluding":"42.2.0","endExcluding":"42.7.11"}42.7.11

References

CWEs

CWE-770

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.