| Name | CVE-2026-14681 |
| Description | Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.5 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DSA-6438-1 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| postgresql-13 (PTS) | bullseye | 13.16-0+deb11u1 | fixed |
| bullseye (security) | 13.23-0+deb11u4 | fixed | |
| postgresql-15 (PTS) | bookworm | 15.18-0+deb12u1 | fixed |
| bookworm (security) | 15.19-0+deb12u1 | fixed | |
| postgresql-17 (PTS) | trixie | 17.10-0+deb13u1 | vulnerable |
| trixie (security) | 17.11-0+deb13u1 | fixed | |
| postgresql-18 (PTS) | forky | 18.4-1 | vulnerable |
| sid | 18.6-3 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| postgresql-13 | source | (unstable) | (not affected) | |||
| postgresql-15 | source | (unstable) | (not affected) | |||
| postgresql-17 | source | trixie | 17.11-0+deb13u1 | DSA-6438-1 | ||
| postgresql-17 | source | (unstable) | (unfixed) | |||
| postgresql-18 | source | (unstable) | 18.6-1 |
- postgresql-15 <not-affected> (Vulnerable code not present)
- postgresql-13 <not-affected> (Vulnerable code not present)
https://www.postgresql.org/support/security/CVE-2026-14681/
https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/