Notable Changes
Notable changes
Security
- fix: a
requireAuthvalue that excludes every authentication method, such as!password,!md5,!gss,!sspi,!scram-sha-256,!none, now refuses every method. A connection with such a value fails with SQLState08004and the messageAuthentication method is not allowed by requireAuth; withchannelBinding=requirealso set, the channel binding message comes instead, as the security page describes. A value without a method in it, such as,, now fails with SQLState22023and the messageInvalid authentication method: <value>, where<value>is therequireAuthvalue, for exampleInvalid authentication method: ,. Releases 42.7.11 through 42.7.13 treated both kinds of value as ifrequireAuthwere not set, and accepted any method the server asked for, including cleartextpassword. After the upgrade, a configuration with such a value can no longer connect. Replace the value with a positive list of the methods your server uses. See the Security Advisory for more detail. The following CVE-2026-107314 has been issued. - fix: when an application sends a value shorter than its declared length, for example a
ByteStreamWriterwhosegetLength()is larger than whatwriteTo()writes, the driver pads the value to the declared length with zeros. Releases 42.7.4 through 42.7.13 padded it with bytes of messages sent earlier on the same connection, so the stored value could contain SQL text and parameter values of earlier statements. See the Security Advisory for more detail. The following CVE-2026-107315 has been issued.