VYPR

apk package

chainguard/guacamole-client-jdbc

pkg:apk/chainguard/guacamole-client-jdbc

Vulnerabilities (2)

  • CVE-2026-54291MedJul 6, 2026
    affected < 1.6.0-r15fixed 1.6.0-r15

    pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting i

  • CVE-2026-42198HigApr 29, 2026
    affected < 1.6.0-r7fixed 1.6.0-r7

    pgjdbc is an open source postgresql JDBC Driver. From version 42.2.0 to before version 42.7.11, pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication. A malicious server can instruct the driver to perform SCRAM authentication with a very larg