Home/Product/postgresql jdbc driver
Product

postgresql jdbc driver

10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-42198
>= 42.2.0 and < 42.7.11
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-s
7.5HIGH
CVE-2025-49146
>= 42.7.4 and < 42.7.7
pgjdbc is an open source postgresql JDBC Driver. From 42.7.4 and until 42.7.7, when the PostgreSQL JDBC driver is configured with
8.2HIGH
CVE-2024-1597
< 42.2.28
pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. I
10.0CRITICAL
CVE-2022-41946
>= 42.2.0 and < 42.2.27
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText
4.7MEDIUM
CVE-2022-31197
< 42.2.26
PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database indepe
7.1HIGH
CVE-2022-26520
>= 42.1.0 and <= 42.1.4
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to
9.8CRITICAL
CVE-2022-21724
< 42.2.25
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing sec
7.0HIGH
CVE-2020-13692
< 42.2.13
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
7.7HIGH
CVE-2018-10936
< 42.2.5
A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host na
8.1HIGH
CVE-2012-1618
all versions
Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strin
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin