More Technical Information Than You Can Handle. 
 

.
 

PostgreSQL JDBC 42.7.7 Security update for...

 

The PostgreSQL JDBC team have released version 42.7.7. to address CVE-2025-49146 When the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authentication methods that do not support channel binding (such as password, MD5, GSS, or SSPI authentication). This could allow a man-in-the-middle attacker to intercept connections that users believed were protected by channel binding requirements.
- Download PostgreSQL
- View Press Release
- Visit PostgreSQL

PostgreSQL-Press
Posted: June 12, 2025 |  By: Wissen Schwamm
Recent PostgreSQL-Press related news.
pg_datasentinel 1.0 released
Autobase 2.7.0 released
DBConvert Streams 2.0 released with PostgreSQL CDC and cross-database querying
dotConnect for PostgreSQL 9.1: New Release
pg_ash v1 - Active Session History for PostgreSQL
+ View more PostgreSQL-Press related news +