<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:35:09 +0000</lastBuildDate>
    <item>
      <title>ALSA-2024:1435 — Important: postgresql-jdbc security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2024:1435</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: postgresql-jdbc, AlmaLinux:8: postgresql-jdbc-javadoc&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE (CVE-2024-1597)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: postgresql-jdbc, AlmaLinux:8: postgresql-jdbc-javadoc&lt;/p&gt;
&lt;p&gt;PostgreSQL is an advanced object-relational database management system. The postgresql-jdbc package includes the .jar files needed for Java programs to access a PostgreSQL database.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE (CVE-2024-1597)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2024:1435</guid>
    </item>
    <item>
      <title>bdu:2024-01541</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2024-01541</link>
      <description>bdu:2024-01541</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2024-01541</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0157 — Une vulnérabilité a été découverte dans PostgreSQL JDBC. Elles permet à
un attaquant de provoquer une exécution de code…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0157</link>
      <description>certfr-2024-avi-0157</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0157</guid>
    </item>
    <item>
      <title>EUVD-2026-258519</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-258519</link>
      <description>EUVD-2026-258519</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-258519</guid>
    </item>
    <item>
      <title>fkie_cve-2024-1597</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-1597</link>
      <description>&lt;p&gt;pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.28 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.28 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-1597</guid>
    </item>
    <item>
      <title>GHSA-24rp-q3w6-vc56 — org.postgresql:postgresql vulnerable to SQL Injection via line comment generation</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-24rp-q3w6-vc56</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.postgresql:postgresql&lt;/p&gt;
&lt;p&gt;# Impact
SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code that has a vulnerable SQL that negates a parameter value.&lt;/p&gt;
&lt;p&gt;There is no vulnerability in the driver when using the default query mode. Users that do not override the query mode are not impacted.&lt;/p&gt;
&lt;p&gt;# Exploitation&lt;/p&gt;
&lt;p&gt;To exploit this behavior the following conditions must be met:&lt;/p&gt;
&lt;p&gt;1. A placeholder for a numeric value must be immediately preceded by a minus (i.e. `-`)
1. There must be a second placeholder for a string value after the first placeholder on the same line. 
1. Both parameters must be user controlled.&lt;/p&gt;
&lt;p&gt;The prior behavior of the driver when operating in simple query mode would inline the negative value of the first parameter and cause the resulting line to be treated as a `--` SQL comment. That would extend to the beginning of the next parameter and cause the quoting of that parameter to be consumed by the comment line. If that string parameter includes a newline, the resulting text would appear unescaped in the resulting SQL.&lt;/p&gt;
&lt;p&gt;When operating in the default extended query mode this would not be an issue as the parameter values are sent separately to the server. Only in simple query mode the parameter values are inlined into the executed SQL causing this issue.&lt;/p&gt;
&lt;p&gt;# Example&lt;/p&gt;
&lt;p&gt;```java
PreparedStatement stmt = conn.prepareStatement(&amp;#34;SELECT -?, ?&amp;#34;);
stmt.setInt(1, -1);
stmt.setString(2, &amp;#34;\nWHERE false --&amp;#34;);
ResultSet rs = stmt.executeQue…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.postgresql:postgresql&lt;/p&gt;
&lt;p&gt;# Impact
SQL injection is possible when using the non-default connection property `preferQueryMode=simple` in combination with application code that has a vulnerable SQL that negates a parameter value.&lt;/p&gt;
&lt;p&gt;There is no vulnerability in the driver when using the default query mode. Users that do not override the query mode are not impacted.&lt;/p&gt;
&lt;p&gt;# Exploitation&lt;/p&gt;
&lt;p&gt;To exploit this behavior the following conditions must be met:&lt;/p&gt;
&lt;p&gt;1. A placeholder for a numeric value must be immediately preceded by a minus (i.e. `-`)
1. There must be a second placeholder for a string value after the first placeholder on the same line. 
1. Both parameters must be user controlled.&lt;/p&gt;
&lt;p&gt;The prior behavior of the driver when operating in simple query mode would inline the negative value of the first parameter and cause the resulting line to be treated as a `--` SQL comment. That would extend to the beginning of the next parameter and cause the quoting of that parameter to be consumed by the comment line. If that string parameter includes a newline, the resulting text would appear unescaped in the resulting SQL.&lt;/p&gt;
&lt;p&gt;When operating in the default extended query mode this would not be an issue as the parameter values are sent separately to the server. Only in simple query mode the parameter values are inlined into the executed SQL causing this issue.&lt;/p&gt;
&lt;p&gt;# Example&lt;/p&gt;
&lt;p&gt;```java
PreparedStatement stmt = conn.prepareStatement(&amp;#34;SELECT -?, ?&amp;#34;);
stmt.setInt(1, -1);
stmt.setString(2, &amp;#34;\nWHERE false --&amp;#34;);
ResultSet rs = stmt.executeQue…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-24rp-q3w6-vc56</guid>
    </item>
    <item>
      <title>gsd-2024-1597</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-1597</link>
      <description>gsd-2024-1597</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-1597</guid>
    </item>
    <item>
      <title>OESA-2024-1237 — postgresql-jdbc security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2024-1237</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: postgresql-jdbc, openEuler:20.03-LTS-SP4: postgresql-jdbc, openEuler:22.03-LTS: postgresql-jdbc, openEuler:22.03-LTS-SP1: postgresql-jdbc, openEuler:22.03-LTS-SP2: postgresql-jdbc, openEuler:22.03-LTS-SP3: postgresql-jdbc&lt;/p&gt;
&lt;p&gt;PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. Is an open source JDBC driver written in Pure Java (Type 4), and communicates in the PostgreSQL native network protocol.&#13;
&#13;
Security Fix(es):&#13;
&#13;
pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.8 are affected.(CVE-2024-1597)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: postgresql-jdbc, openEuler:20.03-LTS-SP4: postgresql-jdbc, openEuler:22.03-LTS: postgresql-jdbc, openEuler:22.03-LTS-SP1: postgresql-jdbc, openEuler:22.03-LTS-SP2: postgresql-jdbc, openEuler:22.03-LTS-SP3: postgresql-jdbc&lt;/p&gt;
&lt;p&gt;PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. Is an open source JDBC driver written in Pure Java (Type 4), and communicates in the PostgreSQL native network protocol.&#13;
&#13;
Security Fix(es):&#13;
&#13;
pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.8 are affected.(CVE-2024-1597)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2024-1237</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:13734-1 — postgresql-jdbc-42.7.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13734-1</link>
      <description>&lt;p&gt;postgresql-jdbc-42.7.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;postgresql-jdbc-42.7.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:13734-1</guid>
    </item>
    <item>
      <title>RHBA-2024:2108 — Red Hat Bug Fix Advisory: Red Hat build of Keycloak 24.0.3 Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhba-2024:2108</link>
      <description>&lt;p&gt;pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhba-2024:2108</guid>
    </item>
    <item>
      <title>SUSE-SU-2024:0769-1 — Security update for postgresql-jdbc</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2024:0769-1</link>
      <description>&lt;p&gt;Security update for postgresql-jdbc&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for postgresql-jdbc&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2024:0769-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-1597</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-1597</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libpgjava, Ubuntu:16.04:LTS: libpgjava, Ubuntu:Pro:18.04:LTS: libpgjava, Ubuntu:Pro:20.04:LTS: libpgjava, Ubuntu:22.04:LTS: libpgjava&lt;/p&gt;
&lt;p&gt;pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.28 are affected.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: libpgjava, Ubuntu:16.04:LTS: libpgjava, Ubuntu:Pro:18.04:LTS: libpgjava, Ubuntu:Pro:20.04:LTS: libpgjava, Ubuntu:22.04:LTS: libpgjava&lt;/p&gt;
&lt;p&gt;pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.28 are affected.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-1597</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-0424 — PostgreSQL JDBC Driver: Schwachstelle ermöglicht SQL-Injection</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0424</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PostgreSQL JDBC Driver ausnutzen, um eine SQL-Injection durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in PostgreSQL JDBC Driver ausnutzen, um eine SQL-Injection durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0424</guid>
    </item>
  </channel>
</rss>
