NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Maven Central · #1415 by repository stars
PostgreSQL JDBC Driver Postgresql
Last release today
07 Oct 2026
Ships fairly regularly
a new release about every 3 months
Most releases are documented
notes for 43 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
14 years old
204 releases · first in 2013
This release fixes two security vulnerabilities.
This release fixes two security vulnerabilities.
requireAuth is silently not enforced when the value excludes every authentication method (GHSA-rhp9-mr79-r74h, CVE-2026-107314)Severity: Moderate (CVSS 5.9) | Affected versions: 42.7.11 – 42.7.13
If the requireAuth connection property excluded all six authentication methods the driver knows (for example requireAuth=!password,!md5,!gss,!sspi,!scram-sha-256,!none) or contained no method at all (for example requireAuth=,), the driver applied no restriction and accepted whatever method the server asked for, including cleartext password. An attacker positioned between the application and the server could use this to request cleartext password authentication and receive the database password.
Unset values, positive lists (such as requireAuth=scram-sha-256) and partial exclusions (such as requireAuth=!password,!md5) were not affected, and neither were deployments that do not set requireAuth.
Behavior after upgrading:
08004 and the message Authentication method is not allowed by requireAuth (or the channel binding error when channelBinding=require is also set).requireAuth value.Because affected deployments had this value by mistake, and connections worked normally on affected versions, connections with such a value will fail after upgrading. Replace it with a positive list of the methods your server uses, for example requireAuth=scram-sha-256.
Independently of this fix, use sslmode=verify-full with a trusted CA so that an attacker cannot present a substitute server.
Thanks to @manus-pi for finding and reporting this issue.
Severity: Moderate (CVSS 5.3) | Affected versions: 42.7.4 – 42.7.13
When an application sent a value shorter than the length it declared, the driver padded the missing bytes with data from earlier messages on the same connection instead of zeros, and the server stored them. The stored value could contain SQL text and parameter values of earlier, unrelated statements (up to 8192 bytes, or 16320 with GSS encryption). On pooled connections, those statements could come from other requests. 42.7.3 and earlier padded with zeros.
This is reachable through the following public API when the declared length is larger than the data:
PreparedStatement.setObject(int, ByteStreamWriter)CopyIn.writeToCopy(ByteStreamWriter) and CopyIn.writeToCopy(byte[], int, int)PGCopyOutputStream.write(byte[], int, int) (writes over 64 KiB)LargeObject.write(byte[], int, int)java.sql.Blob.setBytes(long, byte[], int, int)Padding is now always zeros. Applications whose declared length always matches the data were not affected. Values stored by an affected version through such a call may already contain leaked data, so you may want to review affected columns. There is no connection property to disable the old behavior; the workaround on older versions is to make the declared length match the data.
Thanks to @vlsi for finding and reporting this issue.
Full Changelog: REL42.7.13...REL42.7.14
One column per quarter.
docs: add 42.7.13 release changelog @davecramer
Note truncated.
search_path change via GUC_REPORT (PostgreSQL 18+), so cached plans are no longer used against the wrong schema PR #4259reWriteBatchedInserts now merges up to 32768 rows into one multi-values INSERT (bounded by the 65535 bind-parameter limit on the extended protocol) instead of capping at 128, which speeds up batches of few-column rows. The new reWriteBatchedInsertsSize connection property lowers that cap when set; the default of 0 uses that maximum. PR #4207autosave=ALWAYS. Controlled by the new flushCacheOnDdl connection property (default true); set to false for the prior behaviour. PR #4067connectExecutor connection property to customize the Executor used to run the worker task that performs the connection attempt when loginTimeout is in effect. The value is the fully qualified name of a class implementing java.util.concurrent.Executor. With a null value, the default, the driver retains the prior behavior of running the connection attempt on a daemon thread named "PostgreSQL JDBC driver connection thread". The executor must run the task on a thread other than the caller's. Running the attempt on a named thread lets applications that monitor driver-created threads identify it. PR #4165classLoaderStrategy connection property to control which classloaders the driver searches when loading a class named by a connection property, for example socketFactory. The default driver-first now falls back to the thread context classloader when the driver's classloader cannot resolve the class, which fixes class loading in non-flat class paths such as Quarkus and OSGi. Set driver to keep the previous driver-classloader-only behaviour, or context-first to prefer the thread context classloader Issue #2112 PR #4167RECORD, and refcursor PR #4220LargeObject BlobInputStream now skips by seeking instead of reading, and the driver exposes the server version so it can select the 64-bit large-object API where available PR #4204loginTimeout is now a FutureTask (ConnectTask) instead of the hand-rolled ConnectThread. When the caller hits the timeout, the task is now cancelled with cancel(true), which interrupts the worker thread rather than letting it run to completion. This makes the connection attempt interruptible, so loginTimeout can stop a slow connection attempt instead of leaking a thread. As before, a connection that the worker still manages to establish after the caller gives up is closed by the worker so that it does not leak. There are no public API changes and this should only lead to faster background resource cleanup for connections that time out. PR #4120PGXAConnection.ConnectionHandler now rejects setAutoCommit(false) and setSavepoint(...) during an active XA branch, in addition to the long-rejected setAutoCommit(true) / commit() / rollback(). The setSavepoint rejection was already meant to be in place but the guard misspelled the method name as setSavePoint, so savepoints silently went through. Both changes bring the proxy in line with JTA 1.2 §3.4. PR #4114commitPrepared / rollback-of-prepared now return XAER_RMFAIL instead of XAER_RMERR when the underlying connection is left in a non-idle TransactionState. Transaction managers (Geronimo, Narayana, Atomikos) treat XAER_RMFAIL as retryable on a fresh XAResource; the prepared transaction is no longer abandoned. PR #4114getPrimaryKeys from pg_constraint.conkey PR #4202postgresql-<version>.jar and its detached PGP signature, taken from the same signed build that is uploaded to Maven Central, instead of a leftover SNAPSHOT jar Issue #3812 PR #3814Statement#cancel state machine by dropping the redundant CANCELLED state. killTimerTask now waits for the state to return to IDLE directly, which removes a spin-forever case when more than one thread observes the cancel completing PR #1827.BEGIN and the following query to share a network flush Issue #3894 PR #4196reWriteBatchedInserts no longer throws IllegalArgumentException when batching a parameterless INSERT (for example INSERT INTO t VALUES (1, 2)) of 256 rows or more PR #4207CALL in a CallableStatement no longer hides the native call, so OUT parameter registration works for /* comment */ call proc(?, ?) and similar. Parser.modifyJdbcCall now skips leading whitespace and SQL comments (both -- and /* */) before the call, tolerates a trailing comment after a { ... } escape, and no longer adds a spurious comma when moving an OUT parameter into a call whose arguments are only a comment Issue #2538 PR #4209PreparedStatement.toString() no longer throws for a bytea value supplied as text via PGobject. Hex-format values (\x...) are validated and rendered as a bytea literal, and escape-format values are quoted and cast like any other literal Issue #3757 PR #4201contextClassLoader of shared ForkJoinPool.commonPool() worker threads, which previously left unrelated tasks on those threads running with a null classloader Issue #4155 PR #4156PgResultSet#getCharacterStream wraps String in a StringReader PR #4063PGXAConnection no longer saves and restores the underlying connection's JDBC autoCommit flag. All XA-protocol SQL (BEGIN, PREPARE TRANSACTION, COMMIT, ROLLBACK, COMMIT PREPARED, ROLLBACK PREPARED, the recover() SELECT) is sent through QUERY_SUPPRESS_BEGIN, so the caller's autoCommit value is invariant across every XAResource call. Fixes the "2nd phase commit must be issued using an idle connection" failure during recovery on managed datasources that pool connections with autoCommit=false (TomEE, WildFly, WebSphere Liberty) PR #4114PGXAConnection.prepare() now mutates XA state only after PREPARE TRANSACTION succeeds. A failed PREPARE previously left the driver thinking the branch was already prepared, so the follow-up rollback(xid) tried ROLLBACK PREPARED against a non-existent gid and returned XAER_RMERR. Transaction managers (Narayana) escalated this to HeuristicMixedException. With the fix, rollback(xid) takes the active-branch path and issues a plain ROLLBACK, which the server accepts cleanly. Fixes Issue #3153, Issue #3123. PR #4114search_path. When two schemas held a table with the same name and the same primary or unique index name but a different set of key columns, the driver took the union of both schemas' columns, so the result set could be wrongly rejected as not updatable PR #4214. Supersedes PR #3400.LargeObject.close() now flushes a buffered output stream before marking the object closed, so closing a large object without an explicit flush() no longer drops buffered writes. The flush runs while the object is still open (it calls back into LargeObject.write()), and lo_close always runs afterward; a failure from lo_close no longer masks an earlier flush error, and the transaction is not committed when the flush failed Issue #4247 PR #4248.timestamp, timestamptz, and date text with a clear SQLException (SQLState 22007) instead of an ArrayIndexOutOfBoundsException PR #4278CHAR_OCTET_LENGTH for non-character columns PR #4231ResultSet.getBigDecimal(int, int) PR #4211java.time values in an updatable ResultSet updateRow() / insertRow() PR #3848RETURNING clause contains varchar or numeric types PR #4014estimatedReceiveBufferBytes accounting after a forced Sync PR #4014ResultSet for describe-statement purposes, and restore the pre-describe path for generated-key batches PR #4014search_path changes case-insensitively PR #4216.key extension PR #3946KeyStore so FIPS JVMs work PR #4193gssResponseTimeout rather than sslResponseTimeout for GSS connections PR #4076SET LOCAL / SET SESSION TRANSACTION PR #4203AssertionError from BatchResultHandler on a closed connection PR #4187SQL_TSI_FRAC_SECOND with an explicit, explained error PR #4229Driver.acceptsURL with a clear NullPointerException PR #4205NumberParser.getFastLong instead of silently wrapping PR #4163PGInterval.setSeconds PR #4194PgConnection setup fails after connect PR #4161LazyCleanerImpl cleanup task alive across a transient empty queue PR #4038socksNonProxyHosts is set PR #4045ResourceBundle cache on deregister so the driver can unload PR #4237IOException PR #4190java.lang.management dependency in the maxResultBuffer parser PR #4069Notable changes
search_path GUC_REPORT (PG 18+) PR #4259flushCacheOnDdl — re-prepare server statements after CREATE/DROP/ALTER PR #4067connectExecutor (Executor) instead of connectThreadFactory (ThreadFactory) PR #4165classLoaderStrategy for thread-context classloader fallback PR #4167reWriteBatchedInserts by the protocol limit, not 128 PR #4207BlobInputStream by seeking instead of reading PR #4204getPrimaryKeys from pg_constraint.conkey PR #4202Driver.ConnectTask PR #4160test-anorm-sbt module and its CI wiring PR #4261reduced-pom.xml on Java 11+ PR #4157check and CI, skip Jandex for them PR #4235MethodCanBeStatic to error level PR #4172.po files to UTF-8 PR #4115ru.po PR #1280search_path correctness for server-prepared statements PR #4227jdbc:postgresql:/ URL form in connection guide PR #2532search_path visibility PR #4214PreparedStatement#toString PR #4201PGXAConnection no longer saves and restores the caller's autoCommit PR #4114CHAR_OCTET_LENGTH for non-character columns PR #4231ResultSet.getBigDecimal(int, int) PR #4211java.time values in updatable ResultSet updateRow()/insertRow() PR #3848PgResultSet#getCharacterStream wraps String in StringReader PR #4063estimatedReceiveBufferBytes accounting after forced Sync PR #4014search_path changes case-insensitively PR #4216BlobInputStream relative to the LargeObject position PR #4204lo_close mask a flush failure Issue #4247 PR #4248.key extension PR #3946gssResponseTimeout rather than sslResponseTimeout PR #4076SET LOCAL/SESSION TRANSACTION PR #4203AssertionError from BatchResultHandler on a closed connection PR #4187Driver.acceptsURL with a clear NullPointerException PR #4205NumberParser.getFastLong instead of wrapping PR #4163PGInterval.setSeconds PR #4194PgConnection setup fails after connect PR #4161contextClassLoader on shared commonPool workers PR #4156LazyCleanerImpl cleanup task alive across transient empty queue PR #4038socksNonProxyHosts is set PR #4045Statement#cancel PR #1827ResourceBundle cache on deregister so the driver can unload PR #4237java.lang.management dependency in maxResultBuffer parser PR #4069reWriteBatchedInserts no longer throws IllegalArgumentException for a parameterless INSERT of 256+ rows PR #4207timestamp, timestamptz, and date text with a clear error instead of ArrayIndexOutOfBoundsException PR #4278Commits by author
We also thank the translators whose work ships in this release: Federico Campoli (Italian) and Feng Zhihao (Simplified Chinese), and Sergey Mokhov for reviewing the Russian catalog.
Silent channel-binding authentication downgrade ( CVE-2026-54291 )
channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS (with channel binding) to plain SCRAM-SHA-256 (without it), losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection triggers the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash. Examples are Ed25519, Ed448, and post-quantum algorithms.
Two issues combine in releases 42.7.4 through 42.7.11:
The bundled com.ongres.scram:scram-client (3.1 or 3.2) returns an empty byte array instead of failing when it cannot derive the binding hash for such a certificate. This is the library issue tracked as GHSA-p9jg-fcr6-3mhf.
pgJDBC does not enforce channelBinding=require where it matters. ScramAuthenticator checks only that the server advertised a -PLUS mechanism; it neither rejects the empty binding nor checks that the negotiated mechanism uses channel binding. The connection therefore downgrades silently.
Only connections that set channelBinding=require are affected. Under the default prefer policy, and under allow or disable, falling back to plain SCRAM is the documented behaviour.
Releases before 42.7.4 are unaffected, because they do not support channel binding.
channelBinding=require, the driver silently downgraded from SCRAM-SHA-256-PLUS (with channel binding) to plain SCRAM-SHA-256 (without it) when the server presented a certificate whose signature algorithm has no tls-server-end-point channel-binding hash (e.g. Ed25519, Ed448, or post-quantum algorithms). An attacker who can intercept the TLS connection could exploit this to strip channel-binding protection.
The fix enforces channel binding in the driver's own code: it now fails the connection when no binding data can be extracted, and verifies the negotiated mechanism uses channel binding (-PLUS) when require is set.
Only connections that set channelBinding=require are affected. The default prefer policy and releases before 42.7.4 (which introduced channel-binding support) are unaffected.
See the Security Advisory for more detail.
The following CVE-2026-54291 has been issued.Notable changes
channelBinding=require, the driver silently downgraded from SCRAM-SHA-256-PLUS (with channel binding) to plain SCRAM-SHA-256 (without it) when the server presented a certificate whose signature algorithm has no tls-server-end-point channel-binding hash (e.g. Ed25519, Ed448, or post-quantum algorithms). An attacker who can intercept the TLS connection could exploit this to strip channel-binding protection.
The fix enforces channel binding in the driver's own code: it now fails the connection when no binding data can be extracted, and verifies the negotiated mechanism uses channel binding (-PLUS) when require is set.
Only connections that set channelBinding=require are affected. The default prefer policy and releases before 42.7.4 (which introduced channel-binding support) are unaffected.
See the Security Advisory for more detail.
The following CVE-2026-54291 has been issued.See the Security Advisory for more detail. The following CVE-2026-42198 has been issued.
Notable changes
scramMaxIterations connection property (default 100000) to cap iteration counts before computation begins.
See the Security Advisory for more detail.
The following CVE-2026-42198 has been issued.require_auth connection property, aligning with libpq behaviour PR #3895org.checkerframework to 1.0.2, com.gradleup.shadow to 9.4.0 PR #3978ikalnytskyi/action-setup-postgres PR #3966ikalnytskyi/action-setup-postgres PR #4007@vlsi/github-actions-random-matrix npm package PR #4008ConnectionFactory.closeStream with Throwable.addSuppressed PR #3970${{ }} expressions via env to avoid shell injection PR #4006@exception with @throws in getBoolean javadoc PR #4035QueryExecutor#getTransactionState PR #4006@DisabledIfServerVersion annotations with @EnabledForServerVersionRange PR #3939LogicalReplicationTest@BeforeEach to @BeforeAll PR #3967@DisableLogger annotation to suppress expected log warnings in tests PR #3971IOException when sslMode=ALLOW PR #3973connectTimeout when retrying the connection PR #3968sslMode=prefer and sslResponseTimeout kicks in PR #3968SecurityException from setContextClassLoader on ForkJoinPool workers PR #3962compareTo for LogSequenceNumber comparison to handle unsigned values correctly PR #3961IOException to prevent connection hang PR #3957jsonb as PGObject instead of String PR #3956CopyBothResponseTest by using WAL flush LSN PR #3979confirmed_flush_lsn PR #3975LogicalReplicationStatusTest by polling pg_stat_replication PR #3974max_locks_per_transaction is the same in the replica as the primary; correct is_pg_version_less_than PR #3958pg_hba.conf for head so require_auth tests pass PR #3954net.bytebuddy:byte-buddy-parent to v1.18.8net.bytebuddy:byte-buddy-agent to v1.18.8org.junit:junit-bom to v5.14.3org.mockito:mockito-bom to v5.23.0org.ow2.asm:asm-bom to v9.9.1org.apache.bcel:bcel to v6.12.0org.roaringbitmap:roaringbitmap to v1.6.14org.ops4j.pax.url:pax-url-aether to v3.0.2org.openrewrite.rewrite:org.openrewrite.rewrite.gradle.plugin to v7.30.0com.gradleup.shadow Gradle plugin to v9.4.1com.gradleup.nmcp to v1.4.4com.gradle.develocity to v4.4.0biz.aqute.bnd.builder to v7.2.3org.gradlex.build-parameters to v1.4.5org.jetbrains.kotlin.jvm to v2.3.20com.github.lburgazzoli.karaf to v0.5.7com.github.burrunan.s3-build-cache to v1.9.5release-drafter/release-drafter action to v6.4.0github/codeql-action action to v3.35.1codecov/codecov-action action to v5.5.4actions/checkout action to v6actions/configure-pages action to v6actions/create-github-app-token action to v3sbt/sbt to v1.12.9ubuntu:24.04 docker digestCommits by author
Update site for 42.7.10 release @davecramer
Notable changes
Commits by author
Added changelogs for version 42.7.9 @davecramer
Notable changes
Commits by author
Releases are signed with a new PGP key which is generated at GitHub Actions and stored only there @vlsi
BufferedInputStream with FileInputStream @jgardn3r (#3750)BufferedInputStream with FileInputStream PR #3750Notable changes
BufferedInputStream with FileInputStream PR #3750fix: avoid IllegalStateException: Timer already cancelled when StatementCancelTimerTask.run throws a runtime error PR #3778
fix: avoid NullPointerException when cancelling a query if cancel key is not known yet
fix: Change "PST" timezone in TimestampTest to "Pacific Standard Time" PR #3774
fix: traverse the current dimension to get the correct pos in PgArray#calcRemainingDataLength PR #3746
fix: make sure getImportedExportedKeys returns columns in consistent order
fix: Add "SELF_REFERENCING_COL_NAME" field to getTables' ResultSetMetaData to fix NullPointerException PR #3660
fix: unable to open replication connection to servers < 12
fix: avoid closing statement caused by driver's internal ResultSet#close()
fix: return empty metadata for empty catalog names as it was before
fix: Incorrect class comparison in PGXmlFactoryFactory validation
deps: Update dependency om.ongres.scram:scram-client to 3.2
Commits by author
See the Security Advisory for more detail. Reported by George MacKerron The following CVE-2025-49146 has been issued
channel binding required handling to reject non-SASL authenticationNotable changes
channel binding required handling to reject non-SASL authentication
Previously, when channel binding was set to "require", the driver would silently ignore this
requirement for non-SASL authentication methods. This could lead to a false sense of security
when channel binding was explicitly requested but not actually enforced. The fix ensures that when
channel binding is set to "require", the driver will reject connections that use
non-SASL authentication methods or when SASL authentication has not completed properly.
See the Security Advisory for more detail. Reported by George MacKerron
The following CVE-2025-49146 has been issuedDeprecate group startup parms @davecramer
current_database() in queries @kneth (#3526)Note truncated.
Notable changes
Commits by author
regression: revert change in fc60537 PR #3476
Notable changes
Commits by author
Alexander Nesterenok (1):
Dave Cramer (8):
Jorge Solórzano (3):
Lukas Javorsky (1):
Matthias Hanisch (1):
Mauryan Kansara (2):
Mohanad Khaled (1):
Nathan VanBenschoten (1):
Nick Hall (1):
Pavel Raiskup (1):
Pritesh Ranjan (1):
Sasasu (1):
Sophiah Ho (2):
Vladimir Sitnikov (4):
damienb-opt (1):
dh-cloud (1):
test: Deprecate all PostgreSQL versions older than 9.1 PR #3335
Notable changes
Commits by author
Alan (1): Document READ_ONLY_MODE in README PR 3175
Chris [SpareParts365] (1): docs: clarify binaryTransfer and prepareThreshold PR 3338
Christian Beikov (1): Fix PR 3234 - Return -1 as update count for stored procedure calls (#3235)
Dave Cramer (13): bump version to 42.7.4 PR 3164 correct download for jre7 PR 3198 Speed up getDate by parsing bytes instead of String PR 3141 remove self-hosted runner PR 3227 Fix SSL tests PR 3260 Test for +/- infinity double values PR 3294 chore: add PostgreSQL 15, 16, and 17beta1 to CI tests PR 3299 Ensure order of results for getDouble PR 3301 chore: implement direct SSL ALPN connections PR 3252 use docker v2 which changes docker-compose to docker compose PR 3339 Update to 17beta3 PR 3308 switch localhost and auth-test around PR 3343
Guoyu Feng (2): merge two setBinaryStream methodsPR 3165 Fix the bug with incorrect parameters in the setNull method.PR 3165
Hans Ginzel (1): Update use.md, typo PR 3314
Japin Li (1): Replace greater to with greater than PR 3315
Jorge Solórzano (3): Update SCRAM dependency to 3.1 and support channel binding PR 3188 Deprecate all PostgreSQL versions older than 9.1 PR 3335
Philipp Menke (1): Fix PR 3224 - conversion for TIME '24:00' to LocalTime breaks in binary-mode (#3225)
SheerazMajeedM (2): Fixed typos in all source code and documentations PR 3242 Add translation file PR 3276
Vishal Raj (4): validates resultset parameters PR 3167 bug report: PgInterval ignores case for represented interval string PR 3344
Vladimir Sitnikov (9): fix: support PreparedStatement.setBlob(1, Blob) and PreparedStatement.setClob(1, Clob) for lobs that return -1 for length PR 3136 test: test both binaryMode=true,false when creating connections in DatabaseMetaDataTest PR 3231 fix: support bytea in preferQueryMode=simplePR 3243 perf: replace BufferedOutputStream with unsynchronized PgBufferedOutputStream, increase the send buffer size PR 3248 perf: remove PGStream.streamBuffer and reuse PgBufferedOutputStream's buffer when sending data from InputStream PR 3248 feat: add maxSendBufferSize connection property PR 3248 test: improve tests for writeZeros PR 3248 perf: optimize Set<Integer> which are used for checking if oid should be transferred with binary or text PR #3249 fix: remove preDescribe from internalExecuteBatch PR 2883
imran zaheer (1): Docs: Add cancelSignalTimeout in README PR 3190
mmm444 (1): Add support for Infinity::numeric values in ResultSet.getObject PR 3304
chore: gradle config enforces 17+ PR #3147
else if to switchNoSuchMethodError on ByteBuffer#position when running on Java 8Notable changes
else if to switchNoSuchMethodError on ByteBuffer#position when running on Java 8Commits by author
James Howe (1):
Dave Cramer (1):
John Harvey (1):
Setting the parameter to a -ve value creates a line comment. This has been fixed in this version fixes CVE-2024-1597. Reported by Paul Gerste. See the…
SimpleQuery mode to generate a line comment by having a placeholder for a numeric with a -
such as -?. There must be second placeholder for a string immediately after. Setting the parameter to a -ve value creates a line comment.
This has been fixed in this version fixes CVE-2024-1597. Reported by Paul Gerste. See the security advisory for more details. This has been fixed in versions 42.7.2, 42.6.1 42.5.5, 42.4.4, 42.3.9, 42.2.28.jre7. See the security advisory for work arounds.Notable changes
SimpleQuery mode to generate a line comment by having a placeholder for a numeric with a -
such as -?. There must be second placeholder for a string immediately after. Setting the parameter to a -ve value creates a line comment.
This has been fixed in this version fixes CVE-2024-1597. Reported by Paul Gerste. See the security advisory for more details. This has been fixed in versions 42.7.2, 42.6.1 42.5.5, 42.4.4, 42.3.9, 42.2.28.jre7. See the security advisory for work arounds.Commits by author
Vladimir Sitnikov (1): refactor: Document that encodePassword will zero out the password array, and remove driver's default encodePassword PR #3084
Brett Okken (1): perf: Avoid autoboxing bind indexes PR #1244
Dave Cramer (1):
Sehrope Sarkini (1):
perf: improve performance of PreparedStatement.setBlob, BlobInputStream, and BlobOutputStream with dynamic buffer sizing PR #3044
Notable changes
<!--more-->
Commits by author
Vladimir Sitnikov (4):
Dave Cramer (1):
Christian Ullrich (1):
fix: Deprecate for removal PGPoint.setLocation(java.awt.Point) to cut dependency to java.desktop module. PR #2967
java.desktop module. PR #2967Notable changes
Fixes issues introduced in 42.7.0:
DateStyle from ISO to ISO, MDY (it aligns with PostgreSQL defaults), and it will return the
wrong results when server uses non-default DateStyle (see https://github.com/pgjdbc/pgjdbc/issues/3008)java.desktop module. PR #2967<!--more-->
Commits by author
Brendan MacDonell (1):
Dave Cramer (7):
' around log parameter PR #2936Declan Murphy (1):
Faizan Qazi (1):
George Gastaldi (1):
Jelte Fennema (1):
Martin Desruisseaux (1):
java.desktop module. PR #2967Nathan VanBenschoten (1):
Vladimir Sitnikov (3):
com.github.vlsi dependencies at oncemaffe (1):
pip25 (1):
zhurs (1):
title: PostgreSQL JDBC Driver 42.6.2 Released date: 2024-03-14 08:23:00 -0400 categories:
Notable changes
NoSuchMethodError on ByteBuffer#position When Running on Java 8SimpleParameterList did not support type casting for all well known types.Your coding agent can read these notes before it upgrades. Set up the MCP server →