{"id":"GHSA-hq9p-pm7w-8p54","summary":"pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration","details":"### Impact\nWhen the PostgreSQL JDBC driver is configured with channel binding set to `required` (default value is `prefer`), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI  authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements.\n\n### Patches\nTBD\n\n### Workarounds\n\nConfigure `sslMode=verify-full` to prevent MITM attacks.\n\n### References\n\n* https://www.postgresql.org/docs/current/sasl-authentication.html#SASL-SCRAM-SHA-256\n* https://datatracker.ietf.org/doc/html/rfc7677\n* https://datatracker.ietf.org/doc/html/rfc5802","aliases":["BIT-postgresql-jdbc-driver-2025-49146","CVE-2025-49146"],"modified":"2026-09-10T03:50:25.410496896Z","published":"2025-06-11T14:44:04Z","database_specific":{"nvd_published_at":"2025-06-11T15:15:42Z","cwe_ids":["CWE-287"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-06-11T14:44:04Z"},"references":[{"type":"WEB","url":"https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-hq9p-pm7w-8p54"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49146"},{"type":"WEB","url":"https://github.com/pgjdbc/pgjdbc/commit/9217ed16cb2918ab1b6b9258ae97e6ede244d8a0"},{"type":"WEB","url":"https://datatracker.ietf.org/doc/html/rfc5802"},{"type":"WEB","url":"https://datatracker.ietf.org/doc/html/rfc7677"},{"type":"PACKAGE","url":"https://github.com/pgjdbc/pgjdbc"},{"type":"WEB","url":"https://www.postgresql.org/docs/current/sasl-authentication.html#SASL-SCRAM-SHA-256"}],"affected":[{"package":{"name":"org.postgresql:postgresql","ecosystem":"Maven","purl":"pkg:maven/org.postgresql/postgresql"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"42.7.4"},{"fixed":"42.7.7"}]}],"versions":["42.7.4","42.7.5","42.7.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-hq9p-pm7w-8p54/GHSA-hq9p-pm7w-8p54.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}