# CVE-2018-10936

## Summary

- **CVE ID:** CVE-2018-10936
- **Severity:** HIGH
- **CVSS Score:** 8.1 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-297
- **Published:** Aug 30, 2018
- **Last Modified:** Mar 14, 2026

## Description

A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.

## Affected Products

- [UNKNOWN] — PostgreSQL (42.2.5)

## References

- [CNA](http://www.securityfocus.com/bid/105220)
- [CNA](https://www.postgresql.org/about/news/1883/)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10936)
- [CNA](https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.89%
- **EPSS Percentile:** 75.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-19._