pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.28 are affected.
CVE-2024-1597
This critical-severity CVE scores 10.0 under NVD CVSS v3. EPSS exploit probability: 4.8%, top 9% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
A fix is available — apply it.
- CVSS v3
- 10.0
- EG Score
- 10.0(medium)
- EG Risk
- —
- EPSS
- 91.0%
- KEV
- Not listed
Published
February 19, 2024
Last Modified
November 3, 2025
Advisory Details (7)
Auto-updated Jul 18, 2026[SECURITY] [DLA 3812-1] libpgjava security update
https://lists.debian.org/debian-lts-announce/2024/05/msg00007.htmlSQL Injection via line comment generation · Advisory · pgjdbc/pgjdbc · GitHub
https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56oss-security - CVE-2024-1597: PostgreSQL pgjdbc: SQL injection in non-default configuration
http://www.openwall.com/lists/oss-security/2024/04/02/6EDB Docs - CVE-2024-1597 - SQL Injection via line comment generation
https://www.enterprisedb.com/docs/security/assessments/cve-2024-1597/EDB Docs - JDBC Connector v42.7.3.5 - Release notes
https://www.enterprisedb.com/docs/jdbc_connector/latest/01_jdbc_rel_notes/[SECURITY] Fedora 40 Update: postgresql-jdbc-42.7.3-1.fc40 - package-announce - Fedora mailing-lists
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TZQTSMESZD2RJ5XBPSXH3TIQVUW5DIUU/Vendor Advisories for CVE-2024-1597(2)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Patch Availability(13)
| Vendor / Ecosystem | Fixed in / Patch | Released | Source |
|---|---|---|---|
| redhat | pgjdbc | 2024-08-06 | redhat |
| redhat | postgresql-jdbc-0:42.2.3-5.el8_6 | 2024-07-09 | redhat |
| redhat | postgresql-jdbc-0:42.2.3-7.el8_4 | 2024-07-08 | redhat |
| redhat | openshift-serverless-1/logic-swf-devmode-rhel8:1.33.0-5 | 2024-06-24 | redhat |
| redhat | postgresql-jdbc-0:42.2.14-5.el8_8 | 2024-05-23 | redhat |
| redhat | postgresql-jdbc-0:42.2.3-5.el8_2 | 2024-04-30 | redhat |
| redhat | postgresql-jdbc-0:42.2.28-1.el9_0 | 2024-04-23 | redhat |
| redhat | org.postgresql/postgresql:42.5.6.redhat-00001 | 2024-04-22 | redhat |
| redhat | rh-sso-7/sso7-rhel8-operator-bundle:7.6.7-4 | 2024-04-04 | redhat |
| redhat | org.postgresql/postgresql:42.6.1.redhat-00001 | 2024-04-03 | redhat |
| redhat | postgresql-jdbc-0:42.2.28-1.el9_2 | 2024-04-02 | redhat |
| redhat | postgresql-jdbc-0:42.2.14-3.el8_9 | 2024-03-20 | redhat |
| redhat | postgresql-jdbc-0:42.2.28-1.el9_3 | 2024-03-20 | redhat |
Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.
Affected Packages
(1 across 1 ecosystem)
Maven(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.postgresql:postgresql | 42.0.0 ... 9.4.1212.jre7 (98 versions) | 42.2.8 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Additional Vendor Advisories
(13)
Vendors that published advisories for this CVE beyond the curated set above. Broader coverage but minimal per-row detail — click through for the original advisory.
- Red HatRHBA-2024:2108IMPORTANT2024-02-19
RHBA-2024:2108 — Important
- Red HatRHSA-2024:1435IMPORTANT2024-02-19
RHSA-2024:1435 — Important
- Red HatRHSA-2024:1436IMPORTANT2024-02-19
RHSA-2024:1436 — Important
- Red HatRHSA-2024:1649IMPORTANT2024-02-19
RHSA-2024:1649 — Important
- Red HatRHSA-2024:1662IMPORTANT2024-02-19
RHSA-2024:1662 — Important
- Red HatRHSA-2024:1797IMPORTANT2024-02-19
RHSA-2024:1797 — Important
- Red HatRHSA-2024:1999IMPORTANT2024-02-19
RHSA-2024:1999 — Important
- Red HatRHSA-2024:2624IMPORTANT2024-02-19
RHSA-2024:2624 — Important
- Red HatRHSA-2024:3313IMPORTANT2024-02-19
RHSA-2024:3313 — Important
- Red HatRHSA-2024:4057IMPORTANT2024-02-19
RHSA-2024:4057 — Important
- Red HatRHSA-2024:4375IMPORTANT2024-02-19
RHSA-2024:4375 — Important
- Red HatRHSA-2024:4402IMPORTANT2024-02-19
RHSA-2024:4402 — Important
- Red HatRHSA-2024:5056IMPORTANT2024-02-19
RHSA-2024:5056 — Important
Data Freshness Timeline
(refreshed 9× in last 7d / 44× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
Showing the most recent 100 of 103 total refreshes for this CVE.
- 2026-07-22 23:19 UTCEG score recompute
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-21 15:23 UTCEPSS rescore
- 2026-07-20 17:06 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 14:30 UTCEPSS rescore
- 2026-07-19 02:27 UTCEPSS rescore
- 2026-07-18 10:03 UTCEPSS rescore
- 2026-07-18 10:03 UTCEPSS rescore
- 2026-07-15 16:56 UTCEPSS rescore
- 2026-07-15 16:56 UTCEPSS rescore
- 2026-07-15 01:59 UTCEPSS rescore
- 2026-07-15 01:59 UTCEPSS rescore
- 2026-07-14 19:10 UTCOSV refresh
- 2026-07-13 22:28 UTCEPSS rescore
- 2026-07-13 06:11 UTCEPSS rescore
- 2026-07-13 06:11 UTCEPSS rescore
- 2026-07-12 05:45 UTCEPSS rescore
- 2026-07-12 05:45 UTCEPSS rescore
- 2026-07-11 08:26 UTCEPSS rescore
- 2026-07-09 19:09 UTCEPSS rescore
- 2026-07-08 15:13 UTCEPSS rescore
- 2026-07-07 13:45 UTCEPSS rescore
- 2026-07-07 13:45 UTCEPSS rescore
- 2026-07-06 16:26 UTCEPSS rescore
Show 75 moreShow fewer
- 2026-07-06 02:22 UTCEPSS rescore
- 2026-07-06 02:22 UTCEPSS rescore
- 2026-07-05 02:29 UTCEPSS rescore
- 2026-07-04 06:30 UTCEPSS rescore
- 2026-07-04 06:30 UTCEPSS rescore
- 2026-07-01 15:05 UTCEPSS rescore
- 2026-06-30 23:21 UTCEPSS rescore
- 2026-06-30 23:21 UTCEPSS rescore
- 2026-06-28 14:06 UTCEPSS rescore
- 2026-06-28 14:06 UTCEPSS rescore
- 2026-06-28 04:55 UTCEPSS rescore
- 2026-06-27 03:07 UTCEPSS rescore
- 2026-06-27 03:07 UTCEPSS rescore
- 2026-06-26 20:09 UTCOSV refresh
- 2026-06-25 13:48 UTCEPSS rescore
- 2026-06-24 14:04 UTCEPSS rescore
- 2026-06-24 14:04 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-22 14:24 UTCEPSS rescore
- 2026-06-22 14:24 UTCEPSS rescore
- 2026-06-21 14:55 UTCEPSS rescore
- 2026-06-21 14:55 UTCEPSS rescore
- 2026-06-21 01:58 UTCEPSS rescore
- 2026-06-21 01:58 UTCEPSS rescore
- 2026-06-19 19:24 UTCEPSS rescore
- 2026-06-19 19:24 UTCEPSS rescore
- 2026-06-18 17:51 UTCEPSS rescore
- 2026-06-17 17:52 UTCEPSS rescore
- 2026-06-17 17:51 UTCEPSS rescore
- 2026-06-16 17:51 UTCEPSS rescore
- 2026-06-16 17:51 UTCEPSS rescore
- 2026-06-15 17:47 UTCEPSS rescore
- 2026-06-14 23:16 UTCEPSS rescore
- 2026-06-13 22:59 UTCEPSS rescore
- 2026-06-13 22:59 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-12 23:11 UTCEPSS rescore
- 2026-06-11 13:59 UTCEPSS rescore
- 2026-06-11 13:59 UTCEPSS rescore
- 2026-06-10 22:17 UTCEPSS rescore
- 2026-06-10 22:17 UTCEPSS rescore
- 2026-06-10 13:21 UTCEPSS rescore
- 2026-06-10 13:21 UTCEPSS rescore
- 2026-06-09 06:00 UTCOSV refresh
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-07 15:24 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-02 20:12 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-31 22:30 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-29 13:43 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-28 13:44 UTCEPSS rescore
- 2026-05-27 13:40 UTCEPSS rescore
- 2026-05-26 13:43 UTCEPSS rescore
- 2026-05-26 13:43 UTCEPSS rescore
- 2026-05-26 07:18 UTCEPSS rescore
- 2026-05-26 07:18 UTCEPSS rescore
Related CVEs(same vendor + same CWE)
Same vendor
10 shownredhat
Frequently asked(5)
What is CVE-2024-1597?
When was CVE-2024-1597 disclosed?
Is CVE-2024-1597 actively exploited?
What is the CVSS score of CVE-2024-1597?
How do I remediate CVE-2024-1597?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2024-1597
Is Your Infrastructure Affected by CVE-2024-1597?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.