Improper Enforcement of Message Integrity During Transmission in a Communication Channel Affecting postgresql package, versions [17.0,17.11)[18.0,18.5)


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.07% (1st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-POSTGRESQL-19427845
  • published29 Aug 2026
  • disclosed13 Aug 2026
  • creditUnknown

Introduced: 13 Aug 2026

NewCVE-2026-14681  (opens in a new tab)
CWE-924  (opens in a new tab)

How to fix?

Upgrade postgresql to version 17.11, 18.5 or higher.

Overview

Affected versions of this package are vulnerable to Improper Enforcement of Message Integrity During Transmission in a Communication Channel via the negotiation process between GSSAPI and TLS encryption. An attacker can bypass intended authentication and encryption requirements by initiating a direct TLS connection, potentially resulting in data exchange with weaker security controls if TLS settings are less restrictive than GSSAPI settings.

CVSS Base Scores

version 4.0
version 3.1