CVE-2026-14681
PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL
CVSS Score
4.2
EPSS Score
0.0%
EPSS Percentile
0th
Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.
| CWE | CWE-924 |
| Vendor | n/a |
| Product | postgresql |
| Ecosystems | |
| Industries | Technology |
| Published | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a postgresql
Be the first to know when new medium vulnerabilities affecting n/a postgresql are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / PostgreSQL
18 < 18.5 17 < 17.11
References
Credits
The PostgreSQL project thanks p4p3r for reporting this problem.