{"id":"CVE-2026-14681","year":2026,"sequence":14681,"component":"core server","score":4.2,"cvss_version":"3.0","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","first_published":"2026-08-13","source_url":"https://www.postgresql.org/support/security/CVE-2026-14681/","facts":{"affected":{"17":"17","18":"18"},"affected_ranges":[{"from":"17","until":"17.11"},{"from":"18","until":"18.6"}],"cna_url":"https://cveawg.mitre.org/api/cve/CVE-2026-14681","component":"core server","cvss_version":"3.0","description_en":"Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.","first_published":"2026-08-13","fixed":{"17":"17.11","18":"18.6"},"id":"CVE-2026-14681","introduced":{},"published":{"17":"2026-08-13","18":"2026-08-13"},"score":4.2,"title":"PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL","url":"https://www.postgresql.org/support/security/CVE-2026-14681/","vector":"AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"},"reviewed_hash":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_hash":"965b9e2323feab543f3cbeb74c418c3a5b43cbefc6594d2862ff0d24dcf8e6a2","text":{"locale":"en","title":"PostgreSQL improper enforcement of GSSAPI encryption when coupled with SSL","description":"Improper enforcement of message integrity in PostgreSQL GSSAPI support allows a user to negotiate GSSAPI contrary to pg_hba.conf rules, via initial direct TLS connection. Despite a pg_hba.conf that appears to require GSSAPI, the connection may exchange data over TLS encryption alone. If the TLS settings are more permissive than the GSS settings, the connection may continue with lesser protection. Within major versions 17-18, minor versions before PostgreSQL 18.6 and 17.11 are affected. Versions before PostgreSQL 17 are unaffected.","details":null,"format":"plain","provenance":{"fetched_at":"2026-09-26T10:56:06+00:00","path":"compare/security.json","root":"source-data","sha256":"6a65a7884245936f6adaef8709d290d460e999dfce1ad78734fa7c9a324ed325","source_archive_sha256":"8d8ad63581e1d27b3a0f995ded3feb81c265e38b2ac652eb22f022f52c2240ec","source_revision":"004bc292ee31c11f9a41ab007e9d8116bce29a71","source_url":"https://www.postgresql.org/support/security/"},"text_hash":"214891924a338b5f4f7d7a0988c7468e06906d65b7ca8c69839bb0108663206f"},"locales":["en","zh-Hans"],"fixes":[{"major":"17","fixed_version":"17.11","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"17.11","introduced":null,"published":"2026-08-13"}},{"major":"18","fixed_version":"18.6","introduced":null,"published_date":"2026-08-13","facts":{"fixed":"18.6","introduced":null,"published":"2026-08-13"}}],"legacy":[{"source":"center","source_id":109,"observed_at":"2026-10-03 12:08:35.169032+08","raw":{"id":109,"cve":"2026-14681","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","details":"PostgreSQL 的 GSSAPI 支持未正确强制消息完整性，用户可通过初始的直接 TLS 连接，在违反 pg_hba.conf 规则的情况下协商 GSSAPI。即使 pg_hba.conf 看似要求 GSSAPI，连接仍可能只通过 TLS 加密交换数据； 如果 TLS 设置比 GSS 设置宽松，连接就可能在保护较弱的情况下继续。在主版本 17 和 18 中， PostgreSQL 18.6 与 17.11 之前的小版本受此问题影响；PostgreSQL 17 之前的版本不受影响。","component":"core server","cvenumber":202614681,"description":"PostgreSQL 同时使用 SSL 时未正确强制实施 GSSAPI 加密","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":455,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":455,"patch_id":109,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":456,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":456,"patch_id":109,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T08:10:47.078613+08:00","latestminor":11,"firstreldate":"2024-09-26"}}]},{"source":"pgweb","source_id":109,"observed_at":"2026-10-03 12:08:55.967155+08","raw":{"id":109,"cve":"2026-14681","public":true,"vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","details":"PostgreSQL 的 GSSAPI 支持未正确强制消息完整性，用户可通过初始的直接 TLS 连接，在违反 pg_hba.conf 规则的情况下协商 GSSAPI。即使 pg_hba.conf 看似要求 GSSAPI，连接仍可能只通过 TLS 加密交换数据； 如果 TLS 设置比 GSS 设置宽松，连接就可能在保护较弱的情况下继续。在主版本 17 和 18 中， PostgreSQL 18.6 与 17.11 之前的小版本受此问题影响；PostgreSQL 17 之前的版本不受影响。","component":"core server","cvenumber":202614681,"description":"PostgreSQL 同时使用 SSL 时未正确强制实施 GSSAPI 加密","detailslink":"","legacyscore":"","newspost_id":3365},"fixes":[{"source_id":455,"source_version_id":31,"major":"18","fixed_minor":6,"raw":{"id":455,"patch_id":109,"version_id":31,"fixed_minor":6},"version_raw":{"id":31,"tree":18.0,"current":true,"docsgit":"","eoldate":"2030-11-14","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":6,"firstreldate":"2025-09-25"}},{"source_id":456,"source_version_id":30,"major":"17","fixed_minor":11,"raw":{"id":456,"patch_id":109,"version_id":30,"fixed_minor":11},"version_raw":{"id":30,"tree":17.0,"current":false,"docsgit":"","eoldate":"2029-11-08","reldate":"2026-08-13","testing":0,"supported":true,"docsloaded":"2026-09-27T00:10:45.258078+08:00","latestminor":11,"firstreldate":"2024-09-26"}}]}]}
