Siddharth R created FLINK-40243:
-----------------------------------

             Summary: Bump postgresql jdbc driver from 42.5.6 to 42.7.13
                 Key: FLINK-40243
                 URL: https://issues.apache.org/jira/browse/FLINK-40243
             Project: Flink
          Issue Type: Improvement
            Reporter: Siddharth R


The current version 42.5.6 has a direct vulnerability - 
[*CVE-2026-42198*|https://nvd.nist.gov/vuln/detail/CVE-2026-42198] (CVSS 7.5 
HIGH).

{*}Vulnerability{*}: A malicious server can instruct the PostgreSQL JDBC driver 
to
perform SCRAM-SHA-256 authentication with a very large iteration count, causing
the client to exhaust CPU resources — effectively a denial-of-service against
the connection pool.

{*}Affected versions{*}: 42.2.0 through 42.7.10
*Fixed* {*}in{*}: 42.7.11

*Current* - Maven Repository: org.postgresql » postgresql » 42.5.6
*Latest*  - Maven Repository: org.postgresql » postgresql » 42.7.13



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to