Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

ubuntu логотип

CVE-2026-14681

около 1 месяца назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
EPSS: Низкий
redhat логотип

CVE-2026-14681

около 1 месяца назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2026-14681

около 1 месяца назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
EPSS: Низкий
debian логотип

CVE-2026-14681

около 1 месяца назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support ...

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-gfpv-wrhp-wwh6

около 1 месяца назад

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
EPSS: Низкий
fstec логотип

BDU:2026-11965

около 1 месяца назад

Уязвимость компонента GSSAPI системы управления базами данных PostgreSQL, связанная с ошибками смешения типов данных, позволяющая нарушителю проводить атаки типа "человек посередине"

CVSS3: 5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21702-1

16 дней назад

Security update for postgresql17

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4016-1

9 дней назад

Security update for postgresql17

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4013-1

9 дней назад

Security update for postgresql17

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21703-1

16 дней назад

Security update for postgresql18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4015-1

9 дней назад

Security update for postgresql18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:4014-1

9 дней назад

Security update for postgresql18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3942-1

13 дней назад

Security update for postgresql18

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-14681

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-14681

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-14681

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-14681

Improper enforcement of message integrity in PostgreSQL GSSAPI support ...

CVSS3: 4.2
0%
Низкий
около 1 месяца назад
github логотип
GHSA-gfpv-wrhp-wwh6

Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.

CVSS3: 4.2
0%
Низкий
около 1 месяца назад
fstec логотип
BDU:2026-11965

Уязвимость компонента GSSAPI системы управления базами данных PostgreSQL, связанная с ошибками смешения типов данных, позволяющая нарушителю проводить атаки типа "человек посередине"

CVSS3: 5
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21702-1

Security update for postgresql17

16 дней назад
suse-cvrf логотип
SUSE-SU-2026:4016-1

Security update for postgresql17

9 дней назад
suse-cvrf логотип
SUSE-SU-2026:4013-1

Security update for postgresql17

9 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21703-1

Security update for postgresql18

16 дней назад
suse-cvrf логотип
SUSE-SU-2026:4015-1

Security update for postgresql18

9 дней назад
suse-cvrf логотип
SUSE-SU-2026:4014-1

Security update for postgresql18

9 дней назад
suse-cvrf логотип
SUSE-SU-2026:3942-1

Security update for postgresql18

13 дней назад

Уязвимостей на страницу