Skip to content
Threat Feed
medium advisory

Multiple Vulnerabilities in PostgreSQL JDBC Driver

The PostgreSQL JDBC Driver is susceptible to multiple vulnerabilities, including CVE-2022-21724 and CVE-2022-31197, that allow remote attackers to manipulate data and disclose sensitive information.

CVE search metadata

CVE search record: CVE-2022-21724. Severity: high. CVSS: 7.0. EPSS: 3.09%. KEV: no. Product: PostgreSQL JDBC Driver. Brief: Multiple Vulnerabilities in PostgreSQL JDBC Driver. Brief link: https://feed.craftedsignal.io/briefs/2026-10-postgresql-jdbc-vulnerabilities/

CVE search record: CVE-2022-31197. Severity: high. CVSS: 7.1. EPSS: 2.23%. KEV: no. Product: PostgreSQL JDBC Driver. Brief: Multiple Vulnerabilities in PostgreSQL JDBC Driver. Brief link: https://feed.craftedsignal.io/briefs/2026-10-postgresql-jdbc-vulnerabilities/

The PostgreSQL JDBC Driver is affected by multiple security vulnerabilities, specifically tracked under CVE-2022-21724 and CVE-2022-31197. These vulnerabilities arise from improper handling of connection properties and authentication mechanisms within the driver. An attacker capable of influencing the connection parameters or environment where the driver operates could potentially exploit these flaws to bypass intended security controls. Successful exploitation allows for unauthorized data manipulation and the disclosure of sensitive information within applications that rely on the affected PostgreSQL JDBC Driver for database connectivity. Defenders should prioritize updating the driver to a patched version across all integrated environments to mitigate the risk of unauthorized database interactions.

Impact

Successful exploitation of these vulnerabilities can lead to the loss of data integrity via unauthorized modification and the compromise of confidentiality through the exposure of sensitive database content. Organizations utilizing Java-based applications that interface with PostgreSQL databases are primarily at risk, as the JDBC driver is a core dependency for these connections. The potential impact ranges from localized data leaks to broader application-level compromises depending on the application's implementation of database authentication and authorization.

Recommendation

Prioritize auditing the software inventory to identify all applications and services currently utilizing the PostgreSQL JDBC Driver. Evaluate these instances against the patched version requirements provided by the PostgreSQL project and ensure all affected instances are updated to versions that contain security fixes for CVE-2022-21724 and CVE-2022-31197. If immediate patching is not possible, review application connection configurations to identify and restrict any untrusted input that could influence JDBC connection properties or connection strings.


Immediate actions

Inventory all applications using the PostgreSQL JDBC Driver and confirm patch status.

IT Operations 72h

Mitigations

Update PostgreSQL JDBC Driver to the latest version.

immediate Application Security

CVE-2022-21724, CVE-2022-31197