CVE-2026-42198
pgjdbc pgjdbc, Red Hat build of Quarkus 3.27.3.SP2, Red Hat Enterprise Linux 10 취약점
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail. A single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools. In affected versions, loginTimeout did not fully mitiga...
- 대응 우선순위
- 점검
- CVSS
- 7.5
- EPSS
- 0.77% 백분위 52.1% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.04.30