CVE-2025-49146

EUVD-2025-18118
pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements. This vulnerability is fixed in 42.7.7.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 39.44%
Affected Products (NVD)
VendorProductVersion
postgresqlpostgresql_jdbc_driver
42.7.4 ≤
𝑥
< 42.7.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libpgjava
bookworm
42.5.5-0+deb12u1
fixed
bullseye
42.2.15-1+deb11u1
fixed
bullseye (security)
42.2.15-1+deb11u2
fixed
forky
42.7.13-1
fixed
sid
42.7.13-1
fixed
trixie
42.7.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libpgjava
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
ignored
questing
ignored
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage