DEBIAN-CVE-2026-54291

Source
https://security-tracker.debian.org/tracker/CVE-2026-54291
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54291.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-54291
Upstream
Published
2026-07-06T19:17:08Z
Modified
2026-09-01T16:06:50Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.

References

Affected packages

Debian:12 / libpgjava

Package

Name
libpgjava
Purl
pkg:deb/debian/libpgjava?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

42.*
42.5.4-1
42.5.5-0+deb12u1
42.6.0-1
42.6.0-2
42.7.0-1
42.7.1-1
42.7.2-1
42.7.3-1
42.7.3-2
42.7.5-1
42.7.5-2
42.7.6-1
42.7.7-1
42.7.7-2
42.7.8-1
42.7.8-2
42.7.9-1
42.7.10-1
42.7.11-1
42.7.12-1
42.7.13-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54291.json"

Debian:13 / libpgjava

Package

Name
libpgjava
Purl
pkg:deb/debian/libpgjava?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

42.*
42.7.7-1
42.7.7-2
42.7.8-1
42.7.8-2
42.7.9-1
42.7.10-1
42.7.11-1
42.7.12-1
42.7.13-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54291.json"

Debian:14 / libpgjava

Package

Name
libpgjava
Purl
pkg:deb/debian/libpgjava?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
42.7.12-1

Affected versions

42.*
42.7.7-1
42.7.7-2
42.7.8-1
42.7.8-2
42.7.9-1
42.7.10-1
42.7.11-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-54291.json"