<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:13:12.566806+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2024:1435</id>
    <title>ALSA-2024:1435 — Important: postgresql-jdbc security update</title>
    <updated>2026-10-02T12:13:12.992310+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: postgresql-jdbc, AlmaLinux:8: postgresql-jdbc-javadoc</p>
<p>PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.</p>
<p>Security Fix(es):</p>
<p>* PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE (CVE-2024-1597)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2024:1435"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-01541</id>
    <title>bdu:2024-01541</title>
    <updated>2026-10-02T12:13:12.992381+00:00</updated>
    <content>bdu:2024-01541</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-01541"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0157</id>
    <title>certfr-2024-avi-0157 — Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elles permet à
un attaquant de provoquer une exécution de code…</title>
    <updated>2026-10-02T12:13:12.992399+00:00</updated>
    <content>certfr-2024-avi-0157</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-258519</id>
    <title>EUVD-2026-258519</title>
    <updated>2026-10-02T12:13:12.992416+00:00</updated>
    <content>EUVD-2026-258519</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-258519"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-1597</id>
    <title>fkie_cve-2024-1597</title>
    <updated>2026-10-02T12:13:12.992428+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.28 are affected.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-1597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-24rp-q3w6-vc56</id>
    <title>GHSA-24rp-q3w6-vc56 — org.postgresql:postgresql vulnerable to SQL Injection via line comment generation</title>
    <updated>2026-10-02T12:13:12.992453+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.postgresql:postgresql</p>
<p># Impact
SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code that has a vulnerable SQL that negates a parameter value.</p>
<p>There is no vulnerability in the driver when using the default query mode. Users that do not override the query mode are not impacted.</p>
<p># Exploitation</p>
<p>To exploit this behavior the following conditions must be met:</p>
<p>1. A placeholder for a numeric value must be immediately preceded by a minus (i.e. `-`)
1. There must be a second placeholder for a string value after the first placeholder on the same line. 
1. Both parameters must be user controlled.</p>
<p>The prior behavior of the driver when operating in simple query mode would inline the negative value of the first parameter and cause the resulting line to be treated as a `--` SQL comment. That would extend to the beginning of the next parameter and cause the quoting of that parameter to be consumed by the comment line. If that string parameter includes a newline, the resulting text would appear unescaped in the resulting SQL.</p>
<p>When operating in the default extended query mode this would not be an issue as the parameter values are sent separately to the server. Only in simple query mode the parameter values are inlined into the executed SQL causing this issue.</p>
<p># Example</p>
<p>```java
PreparedStatement stmt = conn.prepareStatement("SELECT -?, ?");
stmt.setInt(1, -1);
stmt.setString(2, "\nWHERE false --");
ResultSet rs = stmt.executeQue…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-24rp-q3w6-vc56"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-1597</id>
    <title>gsd-2024-1597</title>
    <updated>2026-10-02T12:13:12.992501+00:00</updated>
    <content>gsd-2024-1597</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-1597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2024-1237</id>
    <title>OESA-2024-1237 — postgresql-jdbc security update</title>
    <updated>2026-10-02T12:13:12.992513+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: postgresql-jdbc, openEuler:20.03-LTS-SP4: postgresql-jdbc, openEuler:22.03-LTS: postgresql-jdbc, openEuler:22.03-LTS-SP1: postgresql-jdbc, openEuler:22.03-LTS-SP2: postgresql-jdbc, openEuler:22.03-LTS-SP3: postgresql-jdbc</p>
<p>PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. Is an open source JDBC driver written in Pure Java (Type 4), and communicates in the PostgreSQL native network protocol.

Security Fix(es):

pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.8 are affected.(CVE-2024-1597)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2024-1237"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13734-1</id>
    <title>openSUSE-SU-2024:13734-1 — postgresql-jdbc-42.7.2-1.1 on GA media</title>
    <updated>2026-10-02T12:13:12.992546+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>postgresql-jdbc-42.7.2-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13734-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhba-2024:2108</id>
    <title>RHBA-2024:2108 — Red Hat Bug Fix Advisory: Red Hat build of Keycloak 24.0.3 Update</title>
    <updated>2026-10-02T12:13:12.992564+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhba-2024:2108"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2024:0769-1</id>
    <title>SUSE-SU-2024:0769-1 — Security update for postgresql-jdbc</title>
    <updated>2026-10-02T12:13:12.992581+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for postgresql-jdbc</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2024:0769-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-1597</id>
    <title>UBUNTU-CVE-2024-1597</title>
    <updated>2026-10-02T12:13:12.992596+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: libpgjava, Ubuntu:16.04:LTS: libpgjava, Ubuntu:Pro:18.04:LTS: libpgjava, Ubuntu:Pro:20.04:LTS: libpgjava, Ubuntu:22.04:LTS: libpgjava</p>
<p>pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.28 are affected.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-1597"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0424</id>
    <title>WID-SEC-W-2024-0424 — PostgreSQL JDBC Driver: Schwachstelle ermöglicht SQL-Injection</title>
    <updated>2026-10-02T12:13:12.992623+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PostgreSQL JDBC Driver ausnutzen, um eine SQL-Injection durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0424"/>
  </entry>
</feed>
