{"id":"CVE-2026-42198","aliases":["BIT-postgresql-jdbc-driver-2026-42198","GHSA-98qh-xjc8-98pq"],"url":"https://o3.security/vulnerability/CVE-2026-42198","summary":"pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS","details":"## Summary\npgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication.\n\n### Impact\nA malicious server can instruct the driver to perform SCRAM authentication with a very large iteration count.\nWith a large enough value, the client spends an unbounded amount of CPU time inside PBKDF2 before authentication can fail.\nA single attempt ties up a CPU core. Repeated or concurrent attempts exhaust client CPU and can wedge connection pools.\n\nIn affected versions, `loginTimeout` did not fully mitigate this problem. When `loginTimeout` expired, the caller could stop waiting, but the worker thread performing the connection attempt could continue running and burning CPU inside the SCRAM PBKDF2 computation.\n\nThis issue affects availability. It does **not** provide authentication bypass, privilege escalation, or direct password disclosure.\n\nA user is vulnerable when **all** of the following are true:\n\n1. The connection uses **SCRAM-SHA-256** authentication.\n2. The client reaches a **malicious, compromised, or attacker-controlled PostgreSQL endpoint**.\n3. That endpoint sends a very large SCRAM PBKDF2 iteration count in the `server-first-message`.\n\nIn practice, that can happen in these situations:\n\n- the application lets end users or tenants supply their own database connection details (as in many BI, reporting, analytics, ETL, and low-code platforms), so a user can point the shared client host at a server they control\n- the application accepts connection strings, hostnames, or JDBC URLs from user input, configuration uploaded by users, or other untrusted sources\n- the application is configured to connect to a PostgreSQL server that is itself malicious or later becomes compromised\n- the application connects through an untrusted proxy, relay, tunnel, bastion, or connection-pooling service that can act as the PostgreSQL server\n- an attacker can redirect the client to a fake PostgreSQL endpoint by manipulating DNS, service discovery, Kubernetes service resolution, `/etc/hosts`, environment variables, or similar indirection\n- an active network attacker on the path can impersonate the server because the connection does not strongly verify server identity (for example, `sslmode` lower than `verify-full`, or trusting a CA that signs hosts outside the operator's control)\n\nThe issue is **more damaging** when the application uses connection retries, many parallel connection attempts, or `loginTimeout` and assumes the timeout fully stops the work.\n\n### Patches\nThe patch introduces a new connection property, `scramMaxIterations`, with a default of 100K. The client now rejects SCRAM server messages that advertise more PBKDF2 iterations than the configured cap before starting the PBKDF2 computation begins.\n\n### Workarounds\n\nUntil a patched version of pgjdbc is deployed, the following measures reduce exposure:\n\n1. **Only connect to trusted PostgreSQL servers whose identity is verified.**  \n   Connect only to trusted PostgreSQL servers, and verify server identity with TLS using sslmode=verify-full and a trusted CA.\n   TLS without certificate and hostname verification is not sufficient as an active network attacker can still impersonate the server.\n\n2. **Do not rely on `loginTimeout` as a complete mitigation on unpatched versions.**  \n   On affected versions, `loginTimeout` can stop the waiting caller while the worker thread continues spending CPU.\n\n3. **Avoid SCRAM on untrusted or interceptable connection paths.**  \n   For those paths, use an authentication method that does not let the server choose a SCRAM PBKDF2 iteration count.\n\n4. **Reduce blast radius operationally.**  \n   Limit parallel connection attempts, add retry backoff, isolate connection establishment in a separate worker or process when possible, and apply CPU or container limits where appropriate.\n\n5. **On trusted servers you control, keep SCRAM iteration counts at ordinary values.**  \n   This does not defend against an attacker-controlled server, but it avoids unnecessary client cost when talking to legitimate servers.","published":"2026-04-29T15:58:49.174Z","modified":"2026-09-13T03:30:51.341949462Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.03261,"percentile":0.87417,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.postgresql:postgresql","fixedVersion":"42.7.11"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/pgjdbc/pgjdbc/releases/tag/REL42.7.11"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-42198.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19098"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:22304"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:24348"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:25030"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:52928"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:52929"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:52930"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:52978"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:54532"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:59277"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:59278"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:66488"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:66545"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-42198"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42198.json"},{"type":"ADVISORY","url":"https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-98qh-xjc8-98pq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42198"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2463857"},{"type":"PACKAGE","url":"https://github.com/pgjdbc/pgjdbc"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-13T03:30:51.341949462Z"}}