Siddharth R created FLINK-40243:
-----------------------------------
Summary: Bump postgresql jdbc driver from 42.5.6 to 42.7.13
Key: FLINK-40243
URL: https://issues.apache.org/jira/browse/FLINK-40243
Project: Flink
Issue Type: Improvement
Reporter: Siddharth R
The current version 42.5.6 has a direct vulnerability -
[*CVE-2026-42198*|https://nvd.nist.gov/vuln/detail/CVE-2026-42198] (CVSS 7.5
HIGH).
{*}Vulnerability{*}: A malicious server can instruct the PostgreSQL JDBC driver
to
perform SCRAM-SHA-256 authentication with a very large iteration count, causing
the client to exhaust CPU resources — effectively a denial-of-service against
the connection pool.
{*}Affected versions{*}: 42.2.0 through 42.7.10
*Fixed* {*}in{*}: 42.7.11
*Current* - Maven Repository: org.postgresql » postgresql » 42.5.6
*Latest* - Maven Repository: org.postgresql » postgresql » 42.7.13
--
This message was sent by Atlassian Jira
(v8.20.10#820010)