๐Ÿ” CVE Alert

CVE-2025-12967

HIGH 8.0
CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th

An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. We recommend customers upgrade to the following versions: AWS JDBC Wrapper to v2.6.5, AWS Go Wrapper to 2025-10-17, AWS NodeJS Wrapper to v2.0.1, AWS Python Wrapper to v1.4.0 and AWS PGSQL ODBC driver to v1.0.1

CWE CWE-470
Vendor aws
Product jdbc wrapper
Published Nov 10, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for aws jdbc wrapper

Be the first to know when new high vulnerabilities affecting aws jdbc wrapper are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

AWS / JDBC Wrapper
All versions affected
AWS / Go Wrapper
All versions affected
AWS / NodeJS Wrapper
All versions affected
AWS / Python Wrapper
All versions affected
AWS / ODBC driver
1.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
aws.amazon.com: https://aws.amazon.com/security/security-bulletins/AWS-2025-028/ github.com: https://github.com/aws/aws-advanced-jdbc-wrapper/releases/tag/2.6.5 github.com: https://github.com/aws/aws-advanced-go-wrapper/releases/tag/release-2025-10-17 github.com: https://github.com/aws/aws-advanced-python-wrapper/releases/tag/1.4.0 github.com: https://github.com/aws/aws-pgsql-odbc/releases/tag/1.0.1 github.com: https://github.com/aws/aws-advanced-nodejs-wrapper/releases/tag/2.0.1 github.com: https://github.com/aws/aws-advanced-python-wrapper/security/advisories/GHSA-4jvf-wx3f-2x8q github.com: https://github.com/aws/aws-advanced-jdbc-wrapper/security/advisories/GHSA-7xw4-g7mm-r4hh github.com: https://github.com/aws/aws-pgsql-odbc/security/advisories/GHSA-q327-fgm8-7mxf github.com: https://github.com/aws/aws-advanced-go-wrapper/security/advisories/GHSA-7wq2-32h4-9hc9 github.com: https://github.com/aws/aws-advanced-nodejs-wrapper/security/advisories/GHSA-8wj8-cfxr-9374