Logo
vulnerabilityCVE-2026-14672
Name
CVE-2026-14672
Source
NVD ( link)Debian ( link)
Description
Observable response discrepancy in PostgreSQL SCRAM authentication allows an unauthenticated user to test the existence of a user via observing the SCRAM iteration count. This requires the probed user to have a non-default scram_iterations count, because the authentication challenge for a nonexistent user reports the default scram_iterations. Within major versions 16-18, minor versions before PostgreSQL 18.5, 17.11, and 16.15 are affected. Versions before PostgreSQL 16 are unaffected.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
postgresql
Exploitable

Vulnerability Ratings#


5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
17.11
Not Affected
buildroot
master
18.6
Not Affected
openwrt
master
18.6-r1
Not Affected
openwrt
openwrt-25.12
17.5-r3
Exploitable
yocto
kirkstone
14.22
Exploitable
yocto
scarthgap
16.14
Exploitable