CVE-2026-42198: pgjdbc: Unbounded PBKDF2 iterations in SCRAM authentication allows CPU exhaustion DoS
pgjdbc is vulnerable to a client-side denial of service during SCRAM-SHA-256 authentication.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-42198 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →