Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14663

Опубликовано: 13 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

A flaw was found in PostgreSQL pgcrypto. When using disabled ciphers, a user can recover cleartext data by observing faulty ciphertext. This issue arises because the application may accept encrypted data as input, leading to successful decryption even with an incorrect key. Consequently, the protection offered by the Modification Detection Code (MDC) is lost, resulting in information disclosure.

Отчет

This is a Moderate impact flaw in PostgreSQL's pgcrypto module where disabled ciphers can lead to information disclosure. An attacker could recover cleartext data by observing faulty ciphertext, as the application may accept encrypted input and decrypt it even with an incorrect key, bypassing the Modification Detection Code. This vulnerability primarily affects instances utilizing the pgcrypto module for encryption, potentially exposing sensitive data if specific OpenSSL configurations disable certain ciphers.

Меры по смягчению последствий

To mitigate this vulnerability, administrators should avoid using pgcrypto encryption and decryption operations with ciphers that are disabled by the system's OpenSSL configuration or local security policies. Organizations should proactively review their OpenSSL cipher policies to ensure required cryptographic algorithms are fully supported, or transition to robust, enabled algorithms within pgcrypto. Additionally, applications should treat all encrypted input as untrusted and independently validate data

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10postgresql16Fix deferred
Red Hat Enterprise Linux 10postgresql18Fix deferred
Red Hat Enterprise Linux 6postgresqlFix deferred
Red Hat Enterprise Linux 7postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:12/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 8postgresql:16/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:15/postgresqlFix deferred
Red Hat Enterprise Linux 9postgresql:16/postgresqlFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-312
https://bugzilla.redhat.com/show_bug.cgi?id=2515312postgresql: PostgreSQL pgcrypto: Information disclosure via cleartext storage with disabled ciphers

EPSS

Процентиль: 1%
0.00096
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 6.5
nvd
около 1 месяца назад

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

CVSS3: 6.5
msrc
23 дня назад

PostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext

CVSS3: 6.5
debian
около 1 месяца назад

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a use ...

CVSS3: 6.5
github
около 1 месяца назад

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The OpenSSL version and OpenSSL configuration determine the disabled ciphers. If the application accepts encrypted data as input, decryption will succeed even with the wrong key. This in turn loses the modest protection from the Modification Detection Code (MDC). Affected functions are pgp_sym_encrypt, pgp_sym_decrypt, pgp_pub_encrypt, pgp_pub_decrypt, pgp_sym_encrypt_bytea, pgp_sym_decrypt_bytea, pgp_pub_encrypt_bytea, and pgp_pub_decrypt_bytea. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.

EPSS

Процентиль: 1%
0.00096
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-14663