PostgreSQL JDBC 42.7.14 fixes two CVEs, one leaking earlier SQL into rows
The PostgreSQL JDBC driver team released pgjdbc 42.7.14 as a security release for two CVEs; the PostgreSQL project announced it on 9 October. Both advisories are on the pgjdbc GitHub repository and are worth reading in full, because each describes a configuration that looks fine and works normally while being wrong.
CVE-2026-107314 (GHSA-rhp9-mr79-r74h, moderate, CVSS 5.9): requireAuth that excludes everything enforces nothing. If the requireAuth connection property excludes all six methods the driver knows — for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none — or contains no method at all (requireAuth=,), the driver applied no restriction and accepted whatever the server asked for, including a cleartext password. An attacker between application and server could request cleartext authentication and capture the password. The root cause, per the advisory: AuthMethod.parseRequireAuth returns null both for "unset" and for "nothing allowed", and checkAuth treats null as "no restriction". Positive lists (requireAuth=scram-sha-256) and partial exclusions were always enforced correctly. After the upgrade, such a value refuses every connection with SQLState 08004 — so an affected application will fail on purpose; replace the value with a positive list of the methods your server uses.

CVE-2026-107315 (GHSA-f64h-wr5q-3qf3): short values padded with earlier traffic. When an application sends fewer bytes than the length it declared, versions 42.7.4 through 42.7.13 fill the gap not with zeros but with bytes of messages sent earlier on the same connection — and the server stores them. That can include SQL text and parameter values of unrelated earlier statements, and on a pooled connection those may belong to another user. The advisory lists the entry points: PreparedStatement.setObject with a ByteStreamWriter whose getLength() exceeds what it writes, CopyIn.writeToCopy, PGCopyOutputStream.write, LargeObject.write and Blob.setBytes with a length past the array end. In every case the driver accepted the call without error. GSS-encrypted connections are affected too. The bug came in with a buffer-reuse performance change first released in 42.7.4; 42.7.3 and earlier padded with zeros.
What to do. Upgrade to 42.7.14. Then grep your configuration for requireAuth values made only of exclusions, and your code for ByteStreamWriter, COPY and large-object writes where the declared length is computed separately from the data — those are where stored rows may already contain someone else's bytes. Independently, the advisory's own advice stands: sslmode=verify-full against a trusted CA is what stops a substitute server in the first place.
Sources: PostgreSQL News, "PostgreSQL JDBC 42.7.14 Security update for multiple CVE's", 9 October 2026 — https://www.postgresql.org/about/news/2026-10-07-postgresql-jdbc-42714-security-update-for-multiple-cves-3399 ; advisories — https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-rhp9-mr79-r74h and https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-f64h-wr5q-3qf3