{
    "document": {
        "category": "csaf_base",
        "csaf_version": "2.0",
        "distribution": {
            "tlp": {
                "label": "WHITE"
            }
        },
        "lang": "en",
        "notes": [
            {
                "category": "legal_disclaimer",
                "text": "The Netherlands Cyber Security Center (henceforth: NCSC-NL) maintains this portal to enhance access to its information and vulnerabilities. The use of this information is subject to the following terms and conditions:\n\nThe vulnerabilities disclosed in this portal are gathered by NCSC-NL from a variety of open sources, which the user can retrieve from other platforms. NCSC-NL makes every reasonable effort to ensure that the content of this portal is kept up to date, and that it is accurate and complete. Nevertheless, NCSC-NL cannot entirely rule out the possibility of errors, and therefore cannot give any warranty in respect of its completeness, accuracy or real-time keeping up-to-date. NCSC-NL does not control nor guarantee the accuracy, relevance, timeliness or completeness of information obtained from these external sources. The vulnerabilities disclosed in this portal are intended solely for the convenience of professional parties to take appropriate measures to manage the risks posed to the cybersecurity. No rights can be derived from the information provided therein.\n\nNCSC-NL and the Kingdom of the Netherlands assume no legal liability or responsibility for any damage resulting from either the use or inability of use of the vulnerabilities disclosed in this portal. This includes damage resulting from the inaccuracy of incompleteness of the information contained in it.\nThe information on this page is subject to Dutch law. All disputes related to or arising from the use of this portal regarding the disclosure of vulnerabilities will be submitted to the competent court in The Hague. This choice of means also applies to the court in summary proceedings."
            }
        ],
        "publisher": {
            "category": "coordinator",
            "contact_details": "cert@ncsc.nl",
            "name": "National Cyber Security Centre",
            "namespace": "https://www.ncsc.nl/"
        },
        "title": "CVE-2026-54291",
        "tracking": {
            "current_release_date": "2026-08-19T12:07:45.877250Z",
            "generator": {
                "date": "2026-02-17T15:00:00Z",
                "engine": {
                    "name": "V.E.L.M.A",
                    "version": "1.7"
                }
            },
            "id": "CVE-2026-54291",
            "initial_release_date": "2026-07-06T10:11:52.667499Z",
            "revision_history": [
                {
                    "date": "2026-07-06T10:11:52.667499Z",
                    "number": "1",
                    "summary": "CVE created.| Source created.| CVE status created. (valid)| Products created (1).| References created (4)."
                },
                {
                    "date": "2026-07-06T10:12:02.648017Z",
                    "number": "2",
                    "summary": "NCSC Score created."
                },
                {
                    "date": "2026-07-06T19:34:44.939926Z",
                    "number": "3",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-07-06T19:34:48.586416Z",
                    "number": "4",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-06T19:40:28.402322Z",
                    "number": "5",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (3).| CWES updated (1)."
                },
                {
                    "date": "2026-07-06T19:40:31.530415Z",
                    "number": "6",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-06T20:58:37.345696Z",
                    "number": "7",
                    "summary": "Unknown change."
                },
                {
                    "date": "2026-07-07T00:43:33.246886Z",
                    "number": "8",
                    "summary": "Source created.| CVE status created. (valid)| Products connected (2)."
                },
                {
                    "date": "2026-07-07T00:43:40.481672Z",
                    "number": "9",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-07T06:44:42.066016Z",
                    "number": "10",
                    "summary": "Description created for source."
                },
                {
                    "date": "2026-07-07T14:30:54.547090Z",
                    "number": "11",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-07-07T14:31:03.810239Z",
                    "number": "12",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-09T13:32:37.728468Z",
                    "number": "13",
                    "summary": "CVSS created.| Products created (1).| Product Identifiers created (1)."
                },
                {
                    "date": "2026-07-09T13:32:50.350471Z",
                    "number": "14",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-11T01:32:43.319385Z",
                    "number": "15",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (29).| Product Identifiers created (27).| Products created (6).| References created (5)."
                },
                {
                    "date": "2026-07-11T01:32:50.839368Z",
                    "number": "16",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-13T12:24:34.321623Z",
                    "number": "17",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products created (1).| References created (4)."
                },
                {
                    "date": "2026-07-13T12:24:36.235730Z",
                    "number": "18",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-14T05:00:14.356672Z",
                    "number": "19",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (21).| Products created (23).| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-07-14T05:00:22.595018Z",
                    "number": "20",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-21T09:09:41.020220Z",
                    "number": "21",
                    "summary": "Products created (2).| References created (1)."
                },
                {
                    "date": "2026-07-21T09:09:43.860819Z",
                    "number": "22",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-07-21T18:01:23.769294Z",
                    "number": "23",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| References created (5).| CWES updated (1)."
                },
                {
                    "date": "2026-07-21T19:12:48.748715Z",
                    "number": "24",
                    "summary": "Source created.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (7).| Product Identifiers created (8).| Products created (2).| References created (4).| CWES updated (1)."
                },
                {
                    "date": "2026-07-21T19:12:51.463303Z",
                    "number": "25",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-04T21:43:22.157153Z",
                    "number": "26",
                    "summary": "Products removed (32)."
                },
                {
                    "date": "2026-08-04T21:43:29.154395Z",
                    "number": "27",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-05T08:36:40.256049Z",
                    "number": "28",
                    "summary": "Products connected (32)."
                },
                {
                    "date": "2026-08-11T15:18:55.836967Z",
                    "number": "29",
                    "summary": "Source connected.| CVE status created. (valid)| EPSS created."
                },
                {
                    "date": "2026-08-11T15:19:00.412946Z",
                    "number": "30",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-14T00:28:24.794225Z",
                    "number": "31",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Remediations created (1).| References created (93).| CWES updated (1)."
                },
                {
                    "date": "2026-08-14T00:28:26.675030Z",
                    "number": "32",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-14T10:26:12.173481Z",
                    "number": "33",
                    "summary": "Products connected (1).| Product Identifiers created (1).| References created (2)."
                },
                {
                    "date": "2026-08-14T10:26:13.700053Z",
                    "number": "34",
                    "summary": "NCSC Score updated."
                },
                {
                    "date": "2026-08-14T12:33:31.066802Z",
                    "number": "35",
                    "summary": "Source connected.| CVE status created. (valid)| Description created for source.| CVSS created.| Products connected (1).| Product Remediations created (1).| References created (31).| CWES updated (1)."
                },
                {
                    "date": "2026-08-19T12:06:43.558250Z",
                    "number": "36",
                    "summary": "Source connected.| CVE status created. (valid)| Products connected (11).| References created (3)."
                },
                {
                    "date": "2026-08-19T12:06:45.376420Z",
                    "number": "37",
                    "summary": "NCSC Score updated."
                }
            ],
            "status": "interim",
            "version": "37"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.22",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.22",
                                    "product_id": "CSAFPID-9012403"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <12.1.10",
                                "product": {
                                    "name": "vers:unknown/data center lts <12.1.10",
                                    "product_id": "CSAFPID-9012404"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Bamboo"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center <10.4.2",
                                "product": {
                                    "name": "vers:unknown/data center <10.4.2",
                                    "product_id": "CSAFPID-9012406"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.6",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.6",
                                    "product_id": "CSAFPID-9012408"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <9.4.23",
                                "product": {
                                    "name": "vers:unknown/data center lts <9.4.23",
                                    "product_id": "CSAFPID-9012407"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Bitbucket"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.2.15",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.2.15",
                                    "product_id": "CSAFPID-9012410"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <9.2.23",
                                "product": {
                                    "name": "vers:unknown/data center lts <9.2.23",
                                    "product_id": "CSAFPID-9012409"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Confluence"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.9.13",
                                "product": {
                                    "name": "vers:unknown/<4.9.13",
                                    "product_id": "CSAFPID-9012413"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Crucible"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<4.9.13",
                                "product": {
                                    "name": "vers:unknown/<4.9.13",
                                    "product_id": "CSAFPID-9012411"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Fisheye"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <10.3.24",
                                "product": {
                                    "name": "vers:unknown/data center lts <10.3.24",
                                    "product_id": "CSAFPID-9012405"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/data center lts <11.3.10",
                                "product": {
                                    "name": "vers:unknown/data center lts <11.3.10",
                                    "product_id": "CSAFPID-9012414"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Jira"
                    }
                ],
                "category": "vendor",
                "name": "Atlassian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<42.7.12",
                                "product": {
                                    "name": "vers:unknown/<42.7.12",
                                    "product_id": "CSAFPID-8535968"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "PostgreSQL JDBC Driver"
                    }
                ],
                "category": "vendor",
                "name": "Open Source"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/unknown",
                                "product": {
                                    "name": "vers:unknown/unknown",
                                    "product_id": "CSAFPID-1317175",
                                    "product_identification_helper": {
                                        "cpe": "cpe:/o:redhat:enterprise_linux:-"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Red Hat Enterprise Linux"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/3.27",
                                        "product": {
                                            "name": "vers:rpm/3.27",
                                            "product_id": "CSAFPID-8987906",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:quarkus:3.27::el8"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat build of Quarkus 3.27.5"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:rpm/3.33",
                                        "product": {
                                            "name": "vers:rpm/3.33",
                                            "product_id": "CSAFPID-8982208",
                                            "product_identification_helper": {
                                                "cpe": "cpe:/a:redhat:quarkus:3.33::el8"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Red Hat build of Quarkus 3.33.3"
                            }
                        ],
                        "category": "product_family",
                        "name": "Red Hat build of Quarkus"
                    }
                ],
                "category": "vendor",
                "name": "Red Hat"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<6.3.0.20",
                                "product": {
                                    "name": "vers:unknown/<6.3.0.20",
                                    "product_id": "CSAFPID-8870553"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/<6.4.0.9",
                                "product": {
                                    "name": "vers:unknown/<6.4.0.9",
                                    "product_id": "CSAFPID-8870554"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "Sterling Connect:Direct"
                    }
                ],
                "category": "vendor",
                "name": "IBM"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-1394017"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpgjava"
                            }
                        ],
                        "category": "product_family",
                        "name": "bookworm"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:deb/unknown",
                                        "product": {
                                            "name": "vers:deb/unknown",
                                            "product_id": "CSAFPID-1394018"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpgjava"
                            }
                        ],
                        "category": "product_family",
                        "name": "bullseye"
                    }
                ],
                "category": "vendor",
                "name": "Debian"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.2-1002-1",
                                        "product": {
                                            "name": "vers:unknown/9.2-1002-1",
                                            "product_id": "CSAFPID-6454181",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@9.2-1002-1?arch=source&distro=trusty"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-6454182"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpgjava"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:14.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.2-1002-1",
                                        "product": {
                                            "name": "vers:unknown/9.2-1002-1",
                                            "product_id": "CSAFPID-6454183",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@9.2-1002-1?arch=source&distro=xenial"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-6454184"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpgjava"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:16.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.2.23-1",
                                        "product": {
                                            "name": "vers:unknown/42.2.23-1",
                                            "product_id": "CSAFPID-6454194",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.2.23-1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.2.24-1",
                                        "product": {
                                            "name": "vers:unknown/42.2.24-1",
                                            "product_id": "CSAFPID-6454195",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.2.24-1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.3.1-1",
                                        "product": {
                                            "name": "vers:unknown/42.3.1-1",
                                            "product_id": "CSAFPID-6454196",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.3.1-1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.3.2-1",
                                        "product": {
                                            "name": "vers:unknown/42.3.2-1",
                                            "product_id": "CSAFPID-6454197",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.3.2-1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.3.3-1",
                                        "product": {
                                            "name": "vers:unknown/42.3.3-1",
                                            "product_id": "CSAFPID-6454198",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.3.3-1?arch=source&distro=jammy"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-6454199"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpgjava"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:22.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.5.4-1",
                                        "product": {
                                            "name": "vers:unknown/42.5.4-1",
                                            "product_id": "CSAFPID-6454200",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.5.4-1?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.6.0-2",
                                        "product": {
                                            "name": "vers:unknown/42.6.0-2",
                                            "product_id": "CSAFPID-6454201",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.6.0-2?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.7.0-1",
                                        "product": {
                                            "name": "vers:unknown/42.7.0-1",
                                            "product_id": "CSAFPID-6454202",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.7.0-1?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.7.1-1",
                                        "product": {
                                            "name": "vers:unknown/42.7.1-1",
                                            "product_id": "CSAFPID-6454203",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.7.1-1?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.7.2-1",
                                        "product": {
                                            "name": "vers:unknown/42.7.2-1",
                                            "product_id": "CSAFPID-6454204",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.7.2-1?arch=source&distro=noble"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-6454205"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpgjava"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:24.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.7.5-1",
                                        "product": {
                                            "name": "vers:unknown/42.7.5-1",
                                            "product_id": "CSAFPID-6454206",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.7.5-1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.7.5-2",
                                        "product": {
                                            "name": "vers:unknown/42.7.5-2",
                                            "product_id": "CSAFPID-6454207",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.7.5-2?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.7.7-1",
                                        "product": {
                                            "name": "vers:unknown/42.7.7-1",
                                            "product_id": "CSAFPID-6454208",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.7.7-1?arch=source&distro=questing"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-6454209"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpgjava"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:25.10"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.7.10-1",
                                        "product": {
                                            "name": "vers:unknown/42.7.10-1",
                                            "product_id": "CSAFPID-8622930",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.7.10-1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.7.7-1",
                                        "product": {
                                            "name": "vers:unknown/42.7.7-1",
                                            "product_id": "CSAFPID-8622926",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.7.7-1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.7.8-1",
                                        "product": {
                                            "name": "vers:unknown/42.7.8-1",
                                            "product_id": "CSAFPID-8622927",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.7.8-1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.7.8-2",
                                        "product": {
                                            "name": "vers:unknown/42.7.8-2",
                                            "product_id": "CSAFPID-8622928",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.7.8-2?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.7.9-1",
                                        "product": {
                                            "name": "vers:unknown/42.7.9-1",
                                            "product_id": "CSAFPID-8622929",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.7.9-1?arch=source&distro=resolute"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-8622931"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpgjava"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:26.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.4.1212-1",
                                        "product": {
                                            "name": "vers:unknown/9.4.1212-1",
                                            "product_id": "CSAFPID-6454185",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@9.4.1212-1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/9.4.1212-1ubuntu0.1~esm1",
                                        "product": {
                                            "name": "vers:unknown/9.4.1212-1ubuntu0.1~esm1",
                                            "product_id": "CSAFPID-6454186",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@9.4.1212-1ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-6454187"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpgjava"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:18.04:LTS"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.2.10-1",
                                        "product": {
                                            "name": "vers:unknown/42.2.10-1",
                                            "product_id": "CSAFPID-6454191",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.2.10-1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.2.10-1ubuntu0.1~esm1",
                                        "product": {
                                            "name": "vers:unknown/42.2.10-1ubuntu0.1~esm1",
                                            "product_id": "CSAFPID-6454192",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.2.10-1ubuntu0.1~esm1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.2.6-1",
                                        "product": {
                                            "name": "vers:unknown/42.2.6-1",
                                            "product_id": "CSAFPID-6454188",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.2.6-1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.2.8-1",
                                        "product": {
                                            "name": "vers:unknown/42.2.8-1",
                                            "product_id": "CSAFPID-6454189",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.2.8-1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/42.2.9-1",
                                        "product": {
                                            "name": "vers:unknown/42.2.9-1",
                                            "product_id": "CSAFPID-6454190",
                                            "product_identification_helper": {
                                                "purl": "pkg:deb/ubuntu/libpgjava@42.2.9-1?arch=source&distro=esm-apps/focal"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:unknown/>=0",
                                        "product": {
                                            "name": "vers:unknown/>=0",
                                            "product_id": "CSAFPID-6454193"
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "libpgjava"
                            }
                        ],
                        "category": "product_family",
                        "name": "Ubuntu:Pro:20.04:LTS"
                    }
                ],
                "category": "vendor",
                "name": "Ubuntu"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.0-beta.2",
                                "product": {
                                    "name": "vers:unknown/1.0.0-beta.2",
                                    "product_id": "CSAFPID-8783580"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.9-beta1",
                                "product": {
                                    "name": "vers:unknown/1.9-beta1",
                                    "product_id": "CSAFPID-8783579"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0",
                                "product": {
                                    "name": "vers:unknown/2.0",
                                    "product_id": "CSAFPID-8783575"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0-beta1",
                                "product": {
                                    "name": "vers:unknown/2.0-beta1",
                                    "product_id": "CSAFPID-8783578"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0-beta2",
                                "product": {
                                    "name": "vers:unknown/2.0-beta2",
                                    "product_id": "CSAFPID-8783577"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0-beta3",
                                "product": {
                                    "name": "vers:unknown/2.0-beta3",
                                    "product_id": "CSAFPID-8783576"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1",
                                "product": {
                                    "name": "vers:unknown/2.1",
                                    "product_id": "CSAFPID-8783574"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0",
                                "product": {
                                    "name": "vers:unknown/3.0",
                                    "product_id": "CSAFPID-8783573"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1",
                                "product": {
                                    "name": "vers:unknown/3.1",
                                    "product_id": "CSAFPID-8783572"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.2",
                                "product": {
                                    "name": "vers:unknown/3.2",
                                    "product_id": "CSAFPID-8783571"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=42.7.4|<42.7.12",
                                "product": {
                                    "name": "vers:unknown/>=42.7.4|<42.7.12",
                                    "product_id": "CSAFPID-8537741"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.10",
                                "product": {
                                    "name": "vers:unknown/rel42.7.10",
                                    "product_id": "CSAFPID-8768431"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.11",
                                "product": {
                                    "name": "vers:unknown/rel42.7.11",
                                    "product_id": "CSAFPID-8783581"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.4",
                                "product": {
                                    "name": "vers:unknown/rel42.7.4",
                                    "product_id": "CSAFPID-3764854"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.4-rc1",
                                "product": {
                                    "name": "vers:unknown/rel42.7.4-rc1",
                                    "product_id": "CSAFPID-3764855"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.5",
                                "product": {
                                    "name": "vers:unknown/rel42.7.5",
                                    "product_id": "CSAFPID-3764856"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.5-rc1",
                                "product": {
                                    "name": "vers:unknown/rel42.7.5-rc1",
                                    "product_id": "CSAFPID-3764857"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.6",
                                "product": {
                                    "name": "vers:unknown/rel42.7.6",
                                    "product_id": "CSAFPID-3764858"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.6-rc1",
                                "product": {
                                    "name": "vers:unknown/rel42.7.6-rc1",
                                    "product_id": "CSAFPID-3764859"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.7",
                                "product": {
                                    "name": "vers:unknown/rel42.7.7",
                                    "product_id": "CSAFPID-8768435"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.7-rc1",
                                "product": {
                                    "name": "vers:unknown/rel42.7.7-rc1",
                                    "product_id": "CSAFPID-8768434"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.8",
                                "product": {
                                    "name": "vers:unknown/rel42.7.8",
                                    "product_id": "CSAFPID-8768433"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.9",
                                "product": {
                                    "name": "vers:unknown/rel42.7.9",
                                    "product_id": "CSAFPID-8768432"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "pgjdbc"
                    },
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/42.7.10",
                                "product": {
                                    "name": "vers:unknown/42.7.10",
                                    "product_id": "CSAFPID-6615881",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.postgresql/postgresql@42.7.10"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/42.7.11",
                                "product": {
                                    "name": "vers:unknown/42.7.11",
                                    "product_id": "CSAFPID-8872286",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.postgresql/postgresql@42.7.11"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/42.7.4",
                                "product": {
                                    "name": "vers:unknown/42.7.4",
                                    "product_id": "CSAFPID-5523883",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.postgresql/postgresql@42.7.4"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/42.7.5",
                                "product": {
                                    "name": "vers:unknown/42.7.5",
                                    "product_id": "CSAFPID-5523884",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.postgresql/postgresql@42.7.5"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/42.7.6",
                                "product": {
                                    "name": "vers:unknown/42.7.6",
                                    "product_id": "CSAFPID-5523885",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.postgresql/postgresql@42.7.6"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/42.7.7",
                                "product": {
                                    "name": "vers:unknown/42.7.7",
                                    "product_id": "CSAFPID-6615884",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.postgresql/postgresql@42.7.7"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/42.7.8",
                                "product": {
                                    "name": "vers:unknown/42.7.8",
                                    "product_id": "CSAFPID-6615885",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.postgresql/postgresql@42.7.8"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/42.7.9",
                                "product": {
                                    "name": "vers:unknown/42.7.9",
                                    "product_id": "CSAFPID-6615886",
                                    "product_identification_helper": {
                                        "purl": "pkg:maven/org.postgresql/postgresql@42.7.9"
                                    }
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=42.7.4|<42.7.12",
                                "product": {
                                    "name": "vers:unknown/>=42.7.4|<42.7.12",
                                    "product_id": "CSAFPID-8872287"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "postgresql"
                    }
                ],
                "category": "vendor",
                "name": "pgjdbc"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=42.7.4|<42.7.12",
                                "product": {
                                    "name": "vers:unknown/>=42.7.4|<42.7.12",
                                    "product_id": "CSAFPID-8764351"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "postgresql-jdbc-driver"
                    }
                ],
                "category": "vendor",
                "name": "Bitnami"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/>=42.7.4|<42.7.12",
                                "product": {
                                    "name": "vers:unknown/>=42.7.4|<42.7.12",
                                    "product_id": "CSAFPID-8589079",
                                    "product_identification_helper": {
                                        "cpe": "cpe:2.3:a:postgresql:postgresql_jdbc_driver:*:*:*:*:*:*:*:*"
                                    }
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "postgresql_jdbc_driver"
                    }
                ],
                "category": "vendor",
                "name": "PostgreSQL"
            },
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.0.0-beta.2",
                                "product": {
                                    "name": "vers:unknown/1.0.0-beta.2",
                                    "product_id": "CSAFPID-4535768"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/1.9-beta1",
                                "product": {
                                    "name": "vers:unknown/1.9-beta1",
                                    "product_id": "CSAFPID-4535769"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0",
                                "product": {
                                    "name": "vers:unknown/2.0",
                                    "product_id": "CSAFPID-4535770"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0-beta1",
                                "product": {
                                    "name": "vers:unknown/2.0-beta1",
                                    "product_id": "CSAFPID-4535771"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0-beta2",
                                "product": {
                                    "name": "vers:unknown/2.0-beta2",
                                    "product_id": "CSAFPID-4535772"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.0-beta3",
                                "product": {
                                    "name": "vers:unknown/2.0-beta3",
                                    "product_id": "CSAFPID-4535773"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/2.1",
                                "product": {
                                    "name": "vers:unknown/2.1",
                                    "product_id": "CSAFPID-4535774"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.0",
                                "product": {
                                    "name": "vers:unknown/3.0",
                                    "product_id": "CSAFPID-4533920"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.1",
                                "product": {
                                    "name": "vers:unknown/3.1",
                                    "product_id": "CSAFPID-4533921"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/3.2",
                                "product": {
                                    "name": "vers:unknown/3.2",
                                    "product_id": "CSAFPID-5099837"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.10",
                                "product": {
                                    "name": "vers:unknown/rel42.7.10",
                                    "product_id": "CSAFPID-8783560"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.11",
                                "product": {
                                    "name": "vers:unknown/rel42.7.11",
                                    "product_id": "CSAFPID-8783559"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.4",
                                "product": {
                                    "name": "vers:unknown/rel42.7.4",
                                    "product_id": "CSAFPID-8783570"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.4-rc1",
                                "product": {
                                    "name": "vers:unknown/rel42.7.4-rc1",
                                    "product_id": "CSAFPID-8783569"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.5",
                                "product": {
                                    "name": "vers:unknown/rel42.7.5",
                                    "product_id": "CSAFPID-8783568"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.5-rc1",
                                "product": {
                                    "name": "vers:unknown/rel42.7.5-rc1",
                                    "product_id": "CSAFPID-8783567"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.6",
                                "product": {
                                    "name": "vers:unknown/rel42.7.6",
                                    "product_id": "CSAFPID-8783566"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.6-rc1",
                                "product": {
                                    "name": "vers:unknown/rel42.7.6-rc1",
                                    "product_id": "CSAFPID-8783565"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.7",
                                "product": {
                                    "name": "vers:unknown/rel42.7.7",
                                    "product_id": "CSAFPID-8783564"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.7-rc1",
                                "product": {
                                    "name": "vers:unknown/rel42.7.7-rc1",
                                    "product_id": "CSAFPID-8783563"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.8",
                                "product": {
                                    "name": "vers:unknown/rel42.7.8",
                                    "product_id": "CSAFPID-8783562"
                                }
                            },
                            {
                                "category": "product_version_range",
                                "name": "vers:unknown/rel42.7.9",
                                "product": {
                                    "name": "vers:unknown/rel42.7.9",
                                    "product_id": "CSAFPID-8783561"
                                }
                            }
                        ],
                        "category": "product_name",
                        "name": "scram"
                    }
                ],
                "category": "vendor",
                "name": "ongres"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2026-54291",
            "cwe": {
                "id": "CWE-636",
                "name": "Not Failing Securely ('Failing Open')"
            },
            "notes": [
                {
                    "category": "description",
                    "text": "pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.",
                    "title": "nvd - https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-54291"
                },
                {
                    "category": "description",
                    "text": "pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.",
                    "title": "cveprojectv5 - https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/54xxx/CVE-2026-54291.json"
                },
                {
                    "category": "description",
                    "text": "pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.",
                    "title": "debian - https://security-tracker.debian.org/tracker/CVE-2026-54291"
                },
                {
                    "category": "description",
                    "text": "pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Ubuntu%2FUBUNTU-CVE-2026-54291.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-postgresql-jdbc-driver-2026-54291.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-54291.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "### Impact\n\n`channelBinding=require` connections can be silently downgraded from `SCRAM-SHA-256-PLUS` (with channel binding) to plain `SCRAM-SHA-256` (without it), losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection triggers the downgrade with a certificate whose signature algorithm has no `tls-server-end-point` channel-binding hash. Examples are `Ed25519`, `Ed448`, and post-quantum algorithms.\n\nTwo issues combine in releases 42.7.4 through 42.7.11:\n\n1. The bundled `com.ongres.scram:scram-client` (3.1 or 3.2) returns an empty byte array instead of failing when it cannot derive the binding hash for such a certificate. This is the library issue tracked as [GHSA-p9jg-fcr6-3mhf](https://github.com/ongres/scram/security/advisories/GHSA-p9jg-fcr6-3mhf).\n2. pgJDBC does not enforce `channelBinding=require` where it matters. `ScramAuthenticator` checks only that the server *advertised* a `-PLUS` mechanism; it neither rejects the empty binding nor checks that the *negotiated* mechanism uses channel binding. The connection therefore downgrades silently, and would do so even against a fixed `scram-client`, because the missing enforcement is in pgJDBC's own code.\n\nOnly connections that set `channelBinding=require` are affected. Under the default `prefer` policy, and under `allow` or `disable`, falling back to plain SCRAM is the documented behaviour. Releases before 42.7.4 are unaffected, because they do not support channel binding.\n\n### Patches\n\nFixed in pgJDBC 42.7.12. pgJDBC now enforces channel binding in its own code, independently of the `scram-client` version:\n\n- Under `channelBinding=require`, it fails the connection when no channel-binding data can be extracted from the server certificate, instead of passing an empty value to the SCRAM client. The error names the certificate signature algorithm.\n- After negotiation, it requires the selected mechanism to use channel binding (a `-PLUS` mechanism) whenever `channelBinding=require` is set, regardless of how negotiation resolved.\n\nUpgrade to 42.7.12 or later.\n\n### Workarounds\n\nNo pgJDBC setting restores channel-binding enforcement on an affected release; upgrading is the fix.\n\nIf you cannot upgrade immediately, verify the server certificate at the TLS layer so that a man-in-the-middle cannot present a substitute certificate. Set `sslmode=verify-full` with a truststore that contains only your server's CA. This defence is independent of channel binding and blocks the same attacker. Connections that rely on `channelBinding=require` in place of certificate verification have no equivalent workaround and should upgrade.\n\n### References\n\n-  [GHSA-p9jg-fcr6-3mhf](https://github.com/ongres/scram/security/advisories/GHSA-p9jg-fcr6-3mhf) — the related `com.ongres.scram:scram-client` issue (root cause of the empty channel-binding value).\n- `scram-client` 3.3 release (library fix): https://github.com/ongres/scram/releases/tag/3.3\n- pgJDBC fix in 42.7.12: [commit](https://github.com/pgjdbc/pgjdbc/commit/77df98e4e66c12936ded3478a0954f6f580bad99)",
                    "title": "github - https://api.github.com/advisories/GHSA-j92g-9f8w-j867"
                },
                {
                    "category": "description",
                    "text": "### Impact\n\n`channelBinding=require` connections can be silently downgraded from `SCRAM-SHA-256-PLUS` (with channel binding) to plain `SCRAM-SHA-256` (without it), losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection triggers the downgrade with a certificate whose signature algorithm has no `tls-server-end-point` channel-binding hash. Examples are `Ed25519`, `Ed448`, and post-quantum algorithms.\n\nTwo issues combine in releases 42.7.4 through 42.7.11:\n\n1. The bundled `com.ongres.scram:scram-client` (3.1 or 3.2) returns an empty byte array instead of failing when it cannot derive the binding hash for such a certificate. This is the library issue tracked as [GHSA-p9jg-fcr6-3mhf](https://github.com/ongres/scram/security/advisories/GHSA-p9jg-fcr6-3mhf).\n2. pgJDBC does not enforce `channelBinding=require` where it matters. `ScramAuthenticator` checks only that the server *advertised* a `-PLUS` mechanism; it neither rejects the empty binding nor checks that the *negotiated* mechanism uses channel binding. The connection therefore downgrades silently, and would do so even against a fixed `scram-client`, because the missing enforcement is in pgJDBC's own code.\n\nOnly connections that set `channelBinding=require` are affected. Under the default `prefer` policy, and under `allow` or `disable`, falling back to plain SCRAM is the documented behaviour. Releases before 42.7.4 are unaffected, because they do not support channel binding.\n\n### Patches\n\nFixed in pgJDBC 42.7.12. pgJDBC now enforces channel binding in its own code, independently of the `scram-client` version:\n\n- Under `channelBinding=require`, it fails the connection when no channel-binding data can be extracted from the server certificate, instead of passing an empty value to the SCRAM client. The error names the certificate signature algorithm.\n- After negotiation, it requires the selected mechanism to use channel binding (a `-PLUS` mechanism) whenever `channelBinding=require` is set, regardless of how negotiation resolved.\n\nUpgrade to 42.7.12 or later.\n\n### Workarounds\n\nNo pgJDBC setting restores channel-binding enforcement on an affected release; upgrading is the fix.\n\nIf you cannot upgrade immediately, verify the server certificate at the TLS layer so that a man-in-the-middle cannot present a substitute certificate. Set `sslmode=verify-full` with a truststore that contains only your server's CA. This defence is independent of channel binding and blocks the same attacker. Connections that rely on `channelBinding=require` in place of certificate verification have no equivalent workaround and should upgrade.\n\n### References\n\n-  [GHSA-p9jg-fcr6-3mhf](https://github.com/ongres/scram/security/advisories/GHSA-p9jg-fcr6-3mhf) — the related `com.ongres.scram:scram-client` issue (root cause of the empty channel-binding value).\n- `scram-client` 3.3 release (library fix): https://github.com/ongres/scram/releases/tag/3.3\n- pgJDBC fix in 42.7.12: [commit](https://github.com/pgjdbc/pgjdbc/commit/77df98e4e66c12936ded3478a0954f6f580bad99)",
                    "title": "osv - https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Maven%2FGHSA-j92g-9f8w-j867.json?alt=media"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in pgjdbc, an open-source PostgreSQL JDBC Driver. A remote attacker who can intercept a TLS (Transport Layer Security) connection can silently downgrade connections configured to require channel binding from SCRAM-SHA-256-PLUS to plain SCRAM-SHA-256. This downgrade bypasses the intended man-in-the-middle protection, allowing the attacker to potentially intercept or alter sensitive communication. The vulnerability occurs because the system fails to properly validate the channel binding when a specific type of certificate is used.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:51653.json"
                },
                {
                    "category": "description",
                    "text": "A flaw was found in pgjdbc, an open-source PostgreSQL JDBC Driver. A remote attacker who can intercept a TLS (Transport Layer Security) connection can silently downgrade connections configured to require channel binding from SCRAM-SHA-256-PLUS to plain SCRAM-SHA-256. This downgrade bypasses the intended man-in-the-middle protection, allowing the attacker to potentially intercept or alter sensitive communication. The vulnerability occurs because the system fails to properly validate the channel binding when a specific type of certificate is used.",
                    "title": "redhat - https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:53643.json"
                },
                {
                    "category": "other",
                    "text": "0.00203",
                    "title": "EPSS"
                },
                {
                    "category": "other",
                    "text": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
                    "title": "CVSSV4"
                },
                {
                    "category": "other",
                    "text": "8.2",
                    "title": "CVSSV4 base score"
                },
                {
                    "category": "other",
                    "text": "4.2",
                    "title": "NCSC Score"
                },
                {
                    "category": "other",
                    "text": "There is product data available from source Certbundde, VENDOR FIX as product remediation category, Is related to (a version of) an uncommon product",
                    "title": "NCSC Score top increasing factors"
                },
                {
                    "category": "other",
                    "text": "Is related to a product by vendor Open Source, Is related to an uncommon product vendor",
                    "title": "NCSC Score top decreasing factors"
                }
            ],
            "product_status": {
                "fixed": [
                    "CSAFPID-8982208",
                    "CSAFPID-8987906"
                ],
                "known_affected": [
                    "CSAFPID-8535968",
                    "CSAFPID-8537741",
                    "CSAFPID-1394017",
                    "CSAFPID-1394018",
                    "CSAFPID-8589079",
                    "CSAFPID-6454181",
                    "CSAFPID-6454182",
                    "CSAFPID-6454183",
                    "CSAFPID-6454184",
                    "CSAFPID-6454185",
                    "CSAFPID-6454186",
                    "CSAFPID-6454187",
                    "CSAFPID-6454188",
                    "CSAFPID-6454189",
                    "CSAFPID-6454190",
                    "CSAFPID-6454191",
                    "CSAFPID-6454192",
                    "CSAFPID-6454193",
                    "CSAFPID-6454194",
                    "CSAFPID-6454195",
                    "CSAFPID-6454196",
                    "CSAFPID-6454197",
                    "CSAFPID-6454198",
                    "CSAFPID-6454199",
                    "CSAFPID-6454200",
                    "CSAFPID-6454201",
                    "CSAFPID-6454202",
                    "CSAFPID-6454203",
                    "CSAFPID-6454204",
                    "CSAFPID-6454205",
                    "CSAFPID-6454206",
                    "CSAFPID-6454207",
                    "CSAFPID-6454208",
                    "CSAFPID-6454209",
                    "CSAFPID-8622926",
                    "CSAFPID-8622927",
                    "CSAFPID-8622928",
                    "CSAFPID-8622929",
                    "CSAFPID-8622930",
                    "CSAFPID-8622931",
                    "CSAFPID-8764351",
                    "CSAFPID-3764854",
                    "CSAFPID-3764855",
                    "CSAFPID-3764856",
                    "CSAFPID-3764857",
                    "CSAFPID-3764858",
                    "CSAFPID-3764859",
                    "CSAFPID-8768431",
                    "CSAFPID-8768432",
                    "CSAFPID-8768433",
                    "CSAFPID-8768434",
                    "CSAFPID-8768435",
                    "CSAFPID-8783581",
                    "CSAFPID-8870553",
                    "CSAFPID-8870554",
                    "CSAFPID-5523883",
                    "CSAFPID-5523884",
                    "CSAFPID-5523885",
                    "CSAFPID-6615881",
                    "CSAFPID-6615884",
                    "CSAFPID-6615885",
                    "CSAFPID-6615886",
                    "CSAFPID-8872286",
                    "CSAFPID-8872287",
                    "CSAFPID-4533920",
                    "CSAFPID-4533921",
                    "CSAFPID-4535768",
                    "CSAFPID-4535769",
                    "CSAFPID-4535770",
                    "CSAFPID-4535771",
                    "CSAFPID-4535772",
                    "CSAFPID-4535773",
                    "CSAFPID-4535774",
                    "CSAFPID-5099837",
                    "CSAFPID-8783559",
                    "CSAFPID-8783560",
                    "CSAFPID-8783561",
                    "CSAFPID-8783562",
                    "CSAFPID-8783563",
                    "CSAFPID-8783564",
                    "CSAFPID-8783565",
                    "CSAFPID-8783566",
                    "CSAFPID-8783567",
                    "CSAFPID-8783568",
                    "CSAFPID-8783569",
                    "CSAFPID-8783570",
                    "CSAFPID-8783571",
                    "CSAFPID-8783572",
                    "CSAFPID-8783573",
                    "CSAFPID-8783574",
                    "CSAFPID-8783575",
                    "CSAFPID-8783576",
                    "CSAFPID-8783577",
                    "CSAFPID-8783578",
                    "CSAFPID-8783579",
                    "CSAFPID-8783580",
                    "CSAFPID-1317175",
                    "CSAFPID-9012403",
                    "CSAFPID-9012404",
                    "CSAFPID-9012405",
                    "CSAFPID-9012406",
                    "CSAFPID-9012407",
                    "CSAFPID-9012408",
                    "CSAFPID-9012409",
                    "CSAFPID-9012410",
                    "CSAFPID-9012411",
                    "CSAFPID-9012413",
                    "CSAFPID-9012414"
                ]
            },
            "references": [
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2199.json"
                },
                {
                    "category": "external",
                    "summary": "Source - cveprojectv5",
                    "url": "https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/54xxx/CVE-2026-54291.json"
                },
                {
                    "category": "external",
                    "summary": "Source - debian",
                    "url": "https://security-tracker.debian.org/tracker/CVE-2026-54291"
                },
                {
                    "category": "external",
                    "summary": "Source - nvd",
                    "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-54291"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=0"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Ubuntu%2FUBUNTU-CVE-2026-54291.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Bitnami%2FBIT-postgresql-jdbc-driver-2026-54291.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/GIT%2FCVE-2026-54291.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - github",
                    "url": "https://api.github.com/advisories/GHSA-j92g-9f8w-j867"
                },
                {
                    "category": "external",
                    "summary": "Source - osv",
                    "url": "https://www.googleapis.com/download/storage/v1/b/osv-vulnerabilities/o/Maven%2FGHSA-j92g-9f8w-j867.json?alt=media"
                },
                {
                    "category": "external",
                    "summary": "Source - first",
                    "url": "https://api.first.org/data/v1/epss?limit=10000&offset=10000"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:51653.json"
                },
                {
                    "category": "external",
                    "summary": "Source - redhat",
                    "url": "https://access.redhat.com/hydra/rest/securitydata/csaf/RHSA-2026:53643.json"
                },
                {
                    "category": "external",
                    "summary": "Source - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2923.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2199.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2199"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.postgresql.org/about/news/postgresql-jdbc-42712-security-release-3340/"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.tenable.com/cve/CVE-2026-54291"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-j92g-9f8w-j867"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://github.com/pgjdbc/pgjdbc/commit/77df98e4e66c12936ded3478a0954f6f580bad99"
                },
                {
                    "category": "external",
                    "summary": "Reference - cveprojectv5; github; nvd; osv; redhat",
                    "url": "https://github.com/ongres/scram/releases/tag/3.3"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://ubuntu.com/security/CVE-2026-54291"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv; redhat",
                    "url": "https://www.cve.org/CVERecord?id=CVE-2026-54291"
                },
                {
                    "category": "external",
                    "summary": "Reference - github; osv; redhat",
                    "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54291"
                },
                {
                    "category": "external",
                    "summary": "Reference - osv",
                    "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54291.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://www.ibm.com/support/pages/node/7280591"
                },
                {
                    "category": "external",
                    "summary": "Reference - github",
                    "url": "https://github.com/advisories/GHSA-j92g-9f8w-j867"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/cve/CVE-2026-54291"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2497465"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:51653"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/security/updates/classification/#important"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/products/quarkus/"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=3.33.3"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://docs.redhat.com/en/documentation/red_hat_build_of_quarkus/3.33"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-7792"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-7793"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-7794"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-7800"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-7871"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8062"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8064"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8065"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8066"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8067"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8068"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8069"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8070"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8071"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8072"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8073"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8074"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8075"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8076"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8077"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8078"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8079"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8080"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8081"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8082"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8083"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8084"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8085"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8086"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8087"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8088"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8089"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8233"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8234"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8235"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8236"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8237"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8238"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8239"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8240"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8241"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8242"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8243"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8244"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8245"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8246"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8247"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8248"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8249"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8250"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8251"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8252"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8253"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8254"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8255"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8309"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8310"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8311"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8312"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8313"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8314"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8315"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8316"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8317"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8318"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8416"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8417"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8418"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8419"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8420"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8421"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8422"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8423"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8424"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8425"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8426"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8427"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8428"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8543"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8572"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_51653.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde; redhat",
                    "url": "https://access.redhat.com/errata/RHSA-2026:53643"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=redhat.quarkus&downloadType=distributions&version=3.27.5"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://docs.redhat.com/en/documentation/red_hat_build_of_quarkus/3.27"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-7957"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8319"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8320"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8321"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8322"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8323"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8324"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8325"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8326"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8327"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8328"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8329"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8330"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8429"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8430"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8431"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8432"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://issues.redhat.com/browse/QUARKUS-8542"
                },
                {
                    "category": "external",
                    "summary": "Reference - redhat",
                    "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_53643.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2923.json"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2923"
                },
                {
                    "category": "external",
                    "summary": "Reference - certbundde",
                    "url": "https://confluence.atlassian.com/security/security-bulletin-august-18-2026-1821999768.html"
                }
            ],
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Before applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
                    "product_ids": [
                        "CSAFPID-8982208"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:51653"
                },
                {
                    "category": "vendor_fix",
                    "details": "Before applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor information about how to apply this update, see https://access.redhat.com/articles/11258.",
                    "product_ids": [
                        "CSAFPID-8987906"
                    ],
                    "restart_required": {
                        "category": "none"
                    },
                    "url": "https://access.redhat.com/errata/RHSA-2026:53643"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM"
                    },
                    "products": [
                        "CSAFPID-1317175",
                        "CSAFPID-1394017",
                        "CSAFPID-1394018",
                        "CSAFPID-3764854",
                        "CSAFPID-3764855",
                        "CSAFPID-3764856",
                        "CSAFPID-3764857",
                        "CSAFPID-3764858",
                        "CSAFPID-3764859",
                        "CSAFPID-4533920",
                        "CSAFPID-4533921",
                        "CSAFPID-4535768",
                        "CSAFPID-4535769",
                        "CSAFPID-4535770",
                        "CSAFPID-4535771",
                        "CSAFPID-4535772",
                        "CSAFPID-4535773",
                        "CSAFPID-4535774",
                        "CSAFPID-5099837",
                        "CSAFPID-5523883",
                        "CSAFPID-5523884",
                        "CSAFPID-5523885",
                        "CSAFPID-6454181",
                        "CSAFPID-6454182",
                        "CSAFPID-6454183",
                        "CSAFPID-6454184",
                        "CSAFPID-6454185",
                        "CSAFPID-6454186",
                        "CSAFPID-6454187",
                        "CSAFPID-6454188",
                        "CSAFPID-6454189",
                        "CSAFPID-6454190",
                        "CSAFPID-6454191",
                        "CSAFPID-6454192",
                        "CSAFPID-6454193",
                        "CSAFPID-6454194",
                        "CSAFPID-6454195",
                        "CSAFPID-6454196",
                        "CSAFPID-6454197",
                        "CSAFPID-6454198",
                        "CSAFPID-6454199",
                        "CSAFPID-6454200",
                        "CSAFPID-6454201",
                        "CSAFPID-6454202",
                        "CSAFPID-6454203",
                        "CSAFPID-6454204",
                        "CSAFPID-6454205",
                        "CSAFPID-6454206",
                        "CSAFPID-6454207",
                        "CSAFPID-6454208",
                        "CSAFPID-6454209",
                        "CSAFPID-6615881",
                        "CSAFPID-6615884",
                        "CSAFPID-6615885",
                        "CSAFPID-6615886",
                        "CSAFPID-8535968",
                        "CSAFPID-8537741",
                        "CSAFPID-8589079",
                        "CSAFPID-8622926",
                        "CSAFPID-8622927",
                        "CSAFPID-8622928",
                        "CSAFPID-8622929",
                        "CSAFPID-8622930",
                        "CSAFPID-8622931",
                        "CSAFPID-8764351",
                        "CSAFPID-8768431",
                        "CSAFPID-8768432",
                        "CSAFPID-8768433",
                        "CSAFPID-8768434",
                        "CSAFPID-8768435",
                        "CSAFPID-8783559",
                        "CSAFPID-8783560",
                        "CSAFPID-8783561",
                        "CSAFPID-8783562",
                        "CSAFPID-8783563",
                        "CSAFPID-8783564",
                        "CSAFPID-8783565",
                        "CSAFPID-8783566",
                        "CSAFPID-8783567",
                        "CSAFPID-8783568",
                        "CSAFPID-8783569",
                        "CSAFPID-8783570",
                        "CSAFPID-8783571",
                        "CSAFPID-8783572",
                        "CSAFPID-8783573",
                        "CSAFPID-8783574",
                        "CSAFPID-8783575",
                        "CSAFPID-8783576",
                        "CSAFPID-8783577",
                        "CSAFPID-8783578",
                        "CSAFPID-8783579",
                        "CSAFPID-8783580",
                        "CSAFPID-8783581",
                        "CSAFPID-8870553",
                        "CSAFPID-8870554",
                        "CSAFPID-8872286",
                        "CSAFPID-8872287",
                        "CSAFPID-9012403",
                        "CSAFPID-9012404",
                        "CSAFPID-9012405",
                        "CSAFPID-9012406",
                        "CSAFPID-9012407",
                        "CSAFPID-9012408",
                        "CSAFPID-9012409",
                        "CSAFPID-9012410",
                        "CSAFPID-9012411",
                        "CSAFPID-9012413",
                        "CSAFPID-9012414"
                    ]
                }
            ],
            "title": "CVE-2026-54291"
        }
    ]
}