Skip to content
AWSGHSA-7xw4-g7mm-r4hh

Privilege Escalation in Aurora PostgreSQL instance using AWS-JDBC Wrapper

High8.0CVE-2025-12967 · Published Nov 10, 2025

### Description of Vulnerability: An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users. We recommend customers upgrade to the following versions: AWS JDBC Wrapper to v2.6.5 or greater ### Source of Vulnerability Report: Allistair Ishmael Hakim [allistair.hakim@gmail.com](mailto:allistair.hakim@gmail.com) ### Affected products & versions: AWS JDBC Wrapper < 2.6.5 ### Platforms: MacOS/Windows/Linux

GitHub advisory

Affected versions

PackageAffectedFixed in
software.amazon.jdbc:aws-advanced-jdbc-wrapper
Maven
< 2.6.52.6.5
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-470

More AWS advisories

All AWS
Advisory
Defense in depth enhancement for region parameter value in AWS SDK for .NET V4
Low3.7Jan 8
Defense in depth enhancement for region parameter value in AWS SDK for C++
Low3.7Jan 8
Defense in depth enhancement for region parameter value in AWS SDK for JavaScript v3
Low3.7Jan 8
Key Commitment issue in S3 Encryption Client
Medium5.3Dec 17, 2025
Key Commitment issue in S3 Encryption Client
Medium5.3Dec 17, 2025
Key Commitment issue in S3 Encryption Client
Medium5.3Dec 17, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.