Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 13

Количество 13

github логотип

GHSA-98qh-xjc8-98pq

3 месяца назад

pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-42198

3 месяца назад

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitigate this problem. When loginTimeout expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation. This issue has been patched in version 42.7.11.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-42198

3 месяца назад

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitigate this problem. When loginTimeout expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation. This issue has been patched in version 42.7.11.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-42198

3 месяца назад

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitigate this problem. When loginTimeout expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation. This issue has been patched in version 42.7.11.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-42198

3 месяца назад

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 t ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20847-1

2 месяца назад

Security update for postgresql-jdbc

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2028-1

2 месяца назад

Security update for postgresql-jdbc

EPSS: Низкий
rocky логотип

RLSA-2026:25030

около 2 месяцев назад

Important: postgresql-jdbc security update

EPSS: Низкий
rocky логотип

RLSA-2026:24348

около 2 месяцев назад

Important: postgresql-jdbc security update

EPSS: Низкий
rocky логотип

RLSA-2026:22304

2 месяца назад

Important: postgresql-jdbc security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-25030

около 2 месяцев назад

ELSA-2026-25030: postgresql-jdbc security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-24348

17 дней назад

ELSA-2026-24348: postgresql-jdbc security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22304

около 1 месяца назад

ELSA-2026-22304: postgresql-jdbc security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-98qh-xjc8-98pq

pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS

CVSS3: 7.5
1%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-42198

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitigate this problem. When loginTimeout expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation. This issue has been patched in version 42.7.11.

CVSS3: 7.5
1%
Низкий
3 месяца назад
redhat логотип
CVE-2026-42198

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitigate this problem. When loginTimeout expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation. This issue has been patched in version 42.7.11.

CVSS3: 7.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-42198

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitigate this problem. When loginTimeout expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation. This issue has been patched in version 42.7.11.

CVSS3: 7.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-42198

pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 t ...

CVSS3: 7.5
1%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20847-1

Security update for postgresql-jdbc

1%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2028-1

Security update for postgresql-jdbc

1%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:25030

Important: postgresql-jdbc security update

1%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:24348

Important: postgresql-jdbc security update

1%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:22304

Important: postgresql-jdbc security update

1%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2026-25030

ELSA-2026-25030: postgresql-jdbc security update (IMPORTANT)

1%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-24348

ELSA-2026-24348: postgresql-jdbc security update (IMPORTANT)

1%
Низкий
17 дней назад
oracle-oval логотип
ELSA-2026-22304

ELSA-2026-22304: postgresql-jdbc security update (IMPORTANT)

1%
Низкий
около 1 месяца назад

Уязвимостей на страницу