CVE-2026-54291Disclosure(postgresql / postgresql_jdbc_driver)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-636CWE-757

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • postgresql_jdbc_driver

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
postgresql_jdbc_driver

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-02: 1Technical Details · 2026-07-02: 107-02
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve
    Disclosure

    🟠 #PostgreSQL JDBC Driver / SCRAM Client, Silent Channel-Binding Downgrade, #CVE-2026-54291 (Medium) -DC-Jul2026-819 https://dailycve.com/postgresql-jdbc-driver-scram-client-silent-channel-binding-downgrade-cve-2026-54291-medium-dc-jul2026-819/

    Post summary

    The post announces a new CVE (CVE-2026-54291) concerning a silent channel‑binding downgrade in the PostgreSQL JDBC Driver, labeling it Medium severity; no PoC, exploit, or patch information is provided.

    0000049
    218 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppostgresqlpostgresql_jdbc_driver---

Explore more