#1150330 libpgjava: CVE-2026-107315 CVE-2026-107314

Package:
src:libpgjava
Source:
src:libpgjava
Submitter:
Moritz Mühlenhoff
Date:
2026-10-09 09:53:02 UTC
Severity:
normal
Tags:
#1150330#5
Date:
2026-10-08 17:32:38 UTC
From:
To:
Hi,

The following vulnerabilities were published for libpgjava.

CVE-2026-107315[0]:
| pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.4 through 42.7.13
| pads a value that is shorter than its declared length with bytes
| left in its send buffer instead of zeros, and the server stores
| those bytes as part of the value. The bytes are messages the driver
| sent earlier on the same connection: SQL text and parameter values
| of recent statements, which on a pooled connection can come from
| other requests. Each padded value can carry up to 8192 bytes of this
| traffic, or 16320 bytes on a connection with GSS encryption. The
| padding happens when an application declares a length larger than
| the data it supplies, through PreparedStatement.setObject with a
| ByteStreamWriter, CopyIn.writeToCopy, PGCopyOutputStream.write,
| LargeObject.write, or Blob.setBytes. The driver accepts these calls
| without an error. An attacker who can make the application store
| such a value and read it back can collect earlier traffic.
| Applications whose declared lengths always match their data are not
| affected. Versions 42.7.3 and earlier pad with zeros.

https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-f64h-wr5q-3qf3
https://github.com/pgjdbc/pgjdbc/commit/c8998c8e9632a7cdecb128dd7cd122d330b3598a (REL42.7.14)

CVE-2026-107314[1]:
| pgjdbc, the PostgreSQL JDBC Driver, versions 42.7.11 through 42.7.13
| enforce no restriction when the requireAuth connection property
| excludes all six authentication methods the driver knows, for
| example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none.
| The driver then accepts any method the server asks for, including
| cleartext password authentication. A value without a method in it,
| such as requireAuth=, (a single comma), is affected the same way. An
| attacker positioned between the application and its server can ask
| for cleartext password authentication and receive the database
| password. A positive list such as requireAuth=scram-sha-256, and a
| partial exclusion such as requireAuth=!password,!md5, are enforced
| correctly. The property has no default value, so a deployment that
| does not set it is not affected. 42.7.14 fixes the problem: such a
| connection is refused with SQLState 08004, and a value without a
| method in it is rejected as invalid.

https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-rhp9-mr79-r74h
https://github.com/pgjdbc/pgjdbc/commit/a65ef98fe37bf0ecbd1a6331205cdb924985ed75 (REL42.7.14)


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-107315
https://www.cve.org/CVERecord?id=CVE-2026-107315
[1] https://security-tracker.debian.org/tracker/CVE-2026-107314
https://www.cve.org/CVERecord?id=CVE-2026-107314

Please adjust the affected versions in the BTS as needed.

#1150330#10
Date:
2026-10-09 09:29:06 UTC
From:
To:
Hello,

Bug #1150330 in libpostgresql-jdbc-java reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/java-team/libpostgresql-jdbc-java/-/commit/2a969c513914b30805ec2fe82f78d769250f0f89
  + CVE-2026-107315: versions 42.7.4 through 42.7.13 pad a value that is
    shorter than its declared length with bytes left in its send buffer
    instead of zeros, and the server stores those bytes as part of the
    value. The bytes are messages the driver sent earlier on the same
    connection: SQL text and parameter values of recent statements, which on
    a pooled connection can come from other requests. Each padded value can
    carry up to 8192 bytes of this traffic, or 16320 bytes on a connection
    with GSS encryption. The padding happens when an application declares a
    length larger than the data it supplies, through
    PreparedStatement.setObject with a ByteStreamWriter, CopyIn.writeToCopy,
    PGCopyOutputStream.write, LargeObject.write, or Blob.setBytes. The
    driver accepts these calls without an error. An attacker who can make
    the application store such a value and read it back can collect earlier
    traffic. Applications whose declared lengths always match their data are
    not affected. Versions 42.7.3 and earlier pad with zeros.
  + CVE-2026-107314: versions 42.7.11 through 42.7.13 enforce no restriction
    when the requireAuth connection property excludes all six authentication
    methods the driver knows, for example
    requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver
    then accepts any method the server asks for, including cleartext
    password authentication. A value without a method in it, such as
    requireAuth=, (a single comma), is affected the same way. An attacker
    positioned between the application and its server can ask for cleartext
    password authentication and receive the database password. A positive
    list such as requireAuth=scram-sha-256, and a partial exclusion such as
    requireAuth=!password,!md5, are enforced correctly. The property has no
    default value, so a deployment that does not set it is not affected.
    42.7.14 fixes the problem: such a connection is refused with SQLState
    08004, and a value without a method in it is rejected as invalid.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1150330

#1150330#17
Date:
2026-10-09 09:51:29 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libpgjava, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1150330@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Christoph Berg <myon@debian.org> (supplier of updated libpgjava package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 09 Oct 2026 11:14:28 +0200
Source: libpgjava
Architecture: source
Version: 42.7.14-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Christoph Berg <myon@debian.org>
Closes: 1150330
Changes:
 libpgjava (42.7.14-1) unstable; urgency=medium
 .
   * New upstream version 42.7.14. (Closes: #1150330)
     + CVE-2026-107315: versions 42.7.4 through 42.7.13 pad a value that is
       shorter than its declared length with bytes left in its send buffer
       instead of zeros, and the server stores those bytes as part of the
       value. The bytes are messages the driver sent earlier on the same
       connection: SQL text and parameter values of recent statements, which on
       a pooled connection can come from other requests. Each padded value can
       carry up to 8192 bytes of this traffic, or 16320 bytes on a connection
       with GSS encryption. The padding happens when an application declares a
       length larger than the data it supplies, through
       PreparedStatement.setObject with a ByteStreamWriter, CopyIn.writeToCopy,
       PGCopyOutputStream.write, LargeObject.write, or Blob.setBytes. The
       driver accepts these calls without an error. An attacker who can make
       the application store such a value and read it back can collect earlier
       traffic. Applications whose declared lengths always match their data are
       not affected. Versions 42.7.3 and earlier pad with zeros.
     + CVE-2026-107314: versions 42.7.11 through 42.7.13 enforce no restriction
       when the requireAuth connection property excludes all six authentication
       methods the driver knows, for example
       requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none. The driver
       then accepts any method the server asks for, including cleartext
       password authentication. A value without a method in it, such as
       requireAuth=, (a single comma), is affected the same way. An attacker
       positioned between the application and its server can ask for cleartext
       password authentication and receive the database password. A positive
       list such as requireAuth=scram-sha-256, and a partial exclusion such as
       requireAuth=!password,!md5, are enforced correctly. The property has no
       default value, so a deployment that does not set it is not affected.
       42.7.14 fixes the problem: such a connection is refused with SQLState
       08004, and a value without a method in it is rejected as invalid.
Checksums-Sha1:
 944da05a66bf5092fbe5345307a1aef2801681e9 2426 libpgjava_42.7.14-1.dsc
 522aed9be110272187ff0b7b7e5d771acbf6e3a0 1224149 libpgjava_42.7.14.orig.tar.gz
 98c9dda4625a12fac5174dce8a8a51037226d9ec 11764 libpgjava_42.7.14-1.debian.tar.xz
Checksums-Sha256:
 c14c83a5486cf4da479ddab38f3e3b21ac9cdea8f4d97175e5e8a7cef5b566e8 2426 libpgjava_42.7.14-1.dsc
 1f38e5e32f1e9b2200f6c0e7cce02d635d7bc14b35dff803a52e09cd666a16b9 1224149 libpgjava_42.7.14.orig.tar.gz
 5a614a21193cf7ffdfdaf334433307d3628cb10beddc02bd292fc3eb76da26ed 11764 libpgjava_42.7.14-1.debian.tar.xz
Files:
 086da6a46f697a8f81d33dc933aad648 2426 java optional libpgjava_42.7.14-1.dsc
 abe9eb01a66a7a2371e5eb154fd5fc93 1224149 java optional libpgjava_42.7.14.orig.tar.gz
 86e1b2fac82844b291ec4f280671fe72 11764 java optional libpgjava_42.7.14-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXEj+YVf0kXlZcIfGTFprqxLSp64FAmrItU4ACgkQTFprqxLS
p663kQ//QCwMgWr+nYJT1ZbWlwjtGJKzcj8J0tYimgp2gxKZnpk4eIHP+6RLIqcq
293419kM3DUf1gq1pzhxHgwhO+NZQocYiDlUAojaa/4iJDGWKHKxGgMqCyD/DK57
UXKqx6jkYHC6Go6hzeLe6HEU8DgGHkOXUqyoNTZVxh6uJVlT9zTDHr9M0cPc70bP
76kNw9zhDizk9C8Eo7VAloK3E2vcag/mjE0Ceo7c5IU1YWHTB7PZk5uSyqNtb+B9
/A4E1s8aFO4+p9LrrPYKRE1wa4NPSKMuufHvpXCfnpCoFPVCxwiQLtl6GE9wrsvg
TU9YS+L+AuXdgTLyCyGebJLq5QOk8jyDHgCjqIwmFZrxqcEAFdljWbPMUkfXQ5Fq
KkJPjE9fJtg1MMIrU83jPK9KwRGjN06Xzcqcs8gW+bc2UZop8geuj19cHeZWQUaa
39IoXKo3N/1xE0xQz6I3OerV5ByXTS0VIg+z78LUgdD5YazQCtdU2RcKlxNAT5qD
l9UpphixHyKnZ2LBv6j0lnR8fvu4g7ZIUPR8KgGn88rDe1bCHHokAJaMgENg9eNM
tmcwUVb0rNFOYQRagJbO8WffINCRYv4Ms4LScGZox/CqmsNjd7zveZIiW8RM4hlk
HitTys285CMBtQ8PWHEFX5j3yym85p5Cva1SSIeKnX+guJTaZdo=
=bd+B
-----END PGP SIGNATURE-----