PT-2025-25224 · Pgjdbc+2 · Pgjdbc+4

Jawj

·

Published

2025-06-11

·

Updated

2026-01-20

·

CVE-2025-49146

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions pgjdbc versions 42.7.4 through 42.7.6
Description The issue arises when the PostgreSQL JDBC driver is configured with channel binding set to required, allowing connections to proceed with authentication methods that do not support channel binding, such as password, MD5, GSS, or SSPI authentication. This could enable a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements.
Recommendations For pgjdbc versions 42.7.4 through 42.7.6, update to version 42.7.7 to resolve the issue. As a temporary workaround, consider configuring sslMode=verify-full to prevent man-in-the-middle attacks.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-06805
BIT-POSTGRESQL-JDBC-DRIVER-2025-49146
CVE-2025-49146
ECHO-9F55-F2F4-C741
GHSA-HQ9P-PM7W-8P54
OPENSUSE-SU-2025:15264-1

Affected Products

Bamboo
Bitbucket
Confluence
Debian
Pgjdbc