PostgreSQL / Postgresql Jdbc Driver
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-54291 | Silent channel-binding authentication downgrade via unsupported certificate algorithms | HIGH | 8.2 | Jul 6, 2026 |
| CVE-2026-42198 | pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS | HIGH | 7.5 | Apr 29, 2026 |
| CVE-2025-49146 | pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration | HIGH | 8.2 | Jun 11, 2025 |
| CVE-2024-1597 | pgjdbc SQL Injection via line comment generation | CRITICAL | 10.0 | Feb 19, 2024 |
| CVE-2022-41946 | TemporaryFolder on unix-like systems does not limit access to created files in pgjdbc | MEDIUM | 5.5 | Nov 23, 2022 |
| CVE-2022-31197 | SQL Injection in ResultSet.refreshRow() with malicious column names in pgjdbc | HIGH | 8.0 | Aug 3, 2022 |
| CVE-2022-26520 | postgresql-jdbc: Arbitrary File Write Vulnerability | CRITICAL | 9.8 | Mar 7, 2022 |
| CVE-2022-21724 | Unchecked Class Instantiation when providing Plugin Classes | CRITICAL | 9.8 | Feb 2, 2022 |
| CVE-2020-13692 | postgresql-jdbc: XML external entity (XXE) vulnerability in PgSQLXML | HIGH | 7.7 | Jun 4, 2020 |
| CVE-2018-10936 | PostgreSQL: Postgres JDBC driver does not perform host name validation by default | HIGH | 8.1 | Aug 30, 2018 |
| CVE-2012-1618 | postgresql-jdbc: SQL injection due improper escaping of JDBC statement parameters | HIGH | 7.5 | Oct 6, 2012 |
Showing 1 to 11 of 11 CVEs