PostgreSQL: Postgres JDBC driver does not perform host name validation by default
Published Aug 30, 2018
8.1
HIGHCVSS 3.0
EPSS 2.91%
Description
A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.
Affected products
- Vendor n/a Product PostgreSQL Defaultn/a
- Version 42.2.5StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | PostgreSQL | n/a |
|
Configuration 1
- < 42.2.5
Configuration 2
- 6.0
- 7.0
No data.
CloudForms Management Engine 5
postgresql94
Not affected
Red Hat Ansible Tower 3
postgresql96
Not affected
Red Hat Enterprise Linux 6
postgresql-jdbc
Will not fix
Red Hat Enterprise Linux 7
postgresql-jdbc
Fix deferred
Red Hat Enterprise Linux 8
postgresql-jdbc
Fix deferred
Red Hat Mobile Application Platform 4
millicore
Not affected
Red Hat Virtualization 4
postgresql-jdbc
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | postgresql94 | Not affected | n/a |
| Red Hat Ansible Tower 3 | postgresql96 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | postgresql-jdbc | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | postgresql-jdbc | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | postgresql-jdbc | Fix deferred | n/a |
| Red Hat Mobile Application Platform 4 | millicore | Not affected | n/a |
| Red Hat Virtualization 4 | postgresql-jdbc | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Applications using postgresql-jdbc should have their SSL configuration reviewed to ensure that host name verification is not disabled and only trusted CAs are accepted. This vulnerability only impacts usage of postgresql-jdbc with a non-default SSL Factory, provided by the `sslfactory` parameter. If this parameter is not given, the default LibPQFactory is used, which is not vulnerable.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:M/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (27 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.91% (0.02910) | 86.50th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.91% (0.02910) | 85.13th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.89% (0.00892) | 74.85th | v4 (v2025.03.14) |
| Nov 18, 2025 | 2.18% (0.02180) | 82.99th | v4 (v2025.03.14) |
| Jun 19, 2025 | 0.65% (0.00651) | 69.84th | v4 (v2025.03.14) |
| Mar 30, 2025 | 1.93% (0.01927) | 81.73th | v4 (v2025.03.14) |
| Mar 29, 2025 | 16.83% (0.16827) | 91.63th | v4 (v2025.03.14) |
| Mar 28, 2025 | 1.93% (0.01927) | 81.74th | v4 (v2025.03.14) |
| Mar 27, 2025 | 16.83% (0.16827) | 94.05th | v4 (v2025.03.14) |
| Mar 20, 2025 | 10.54% (0.10539) | 92.65th | v4 (v2025.03.14) |
| Mar 19, 2025 | 16.83% (0.16827) | 94.16th | v4 (v2025.03.14) |
| Mar 17, 2025 | 10.54% (0.10539) | 92.70th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.28% (0.00279) | 69.22th | v3 (v2023.03.01) |
| Jun 14, 2024 | 0.35% (0.00354) | 72.06th | v3 (v2023.03.01) |
| Apr 18, 2024 | 0.35% (0.00346) | 71.39th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.39% (0.00387) | 72.47th | v3 (v2023.03.01) |
| Jan 21, 2024 | 0.39% (0.00387) | 70.45th | v3 (v2023.03.01) |
| Dec 9, 2023 | 0.48% (0.00484) | 73.24th | v3 (v2023.03.01) |
| Aug 24, 2023 | 0.49% (0.00489) | 73.05th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.60% (0.00596) | 75.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 15.35% (0.15351) | 95.97th | v2 (v2022.01.01) |
| Apr 1, 2022 | 15.35% (0.15351) | 95.60th | v2 (v2022.01.01) |
| Feb 4, 2022 | 15.35% (0.15351) | 91.59th | v2 (v2022.01.01) |
| Feb 3, 2022 | 4.50% (0.04504) | 76.47th | v1 |
| Jan 6, 2022 | 4.50% (0.04504) | 76.26th | v1 |
| Sep 1, 2021 | 4.50% (0.04504) | 84.13th | v1 |
| Apr 14, 2021 | 4.50% (0.04504) | 0.00th | v1 |
References (10)
- http://www.securityfocus.com/bid/105220 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-10936 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1622225 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10936 x_refsource_CONFIRMIssue TrackingMitigationThird Party Advisory
- https://github.com/advisories/GHSA-568q-9fw5-28wf Advisory
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2018-10936
- https://www.cve.org/CVERecord?id=CVE-2018-10936
- https://www.postgresql.org/about/news/1883/ x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/105220 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-10936 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1622225 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10936 | x_refsource_CONFIRMIssue TrackingMitigationThird Party Advisory | |
| https://github.com/advisories/GHSA-568q-9fw5-28wf | Advisory | |
| https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E | mailing-listx_refsource_MLIST | |
| https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E | ||
| https://nvd.nist.gov/vuln/detail/CVE-2018-10936 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-10936 | ||
| https://www.postgresql.org/about/news/1883/ | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.