THREAT OPS › Threat News › [NVD] CVE-2026-42198 (HIGH 7.5) — pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very larg
[NVD] CVE-2026-42198 (HIGH 7.5) — pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very larg
CVE-2026-42198 CVSS: 7.5 HIGH Published: 2026-04-29T16:16:25.427
pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count. With a large enough value, the clie
Indicators of compromise
- CVE-2026-42198cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-42198