Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-31136

20
FAUCET Score

CVE-2023-31136 is a medium-severity vulnerability affecting PostgresNIO, a Swift client for PostgreSQL, prior to version 1.14.2. It allows a man-in-the-middle attacker to inject false responses to a client's initial queries, even with TLS enabled and certificate verification in place. The vulnerability has a CVSS score of 5.9, indicating a network attack vector with high attack complexity, potentially leading to high confidentiality impact. There are no known active exploits, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.14.2CPE matchmatch criteria
cpe:2.3:a:vapor:postgresnio:*:*:*:*:*:postgresql:*:*

CVSS Data

CVSS version used by this source: 3.1

3.7LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.49%
Probability of exploitation in next 30 days
EPSS Percentile
39.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0049 is in the 6th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
swiftpatch availablevia ghsa
Product: github.com/vapor/postgres-nioFixed in: 1.14.2

Vendor Advisories (1)

swiftGHSA-9cfh-vx93-84vvlow

PostgresNIO processes unencrypted bytes from man-in-the-middle

May 10, 2023

References

github.com / advisories/GHSA-467w-rrqc-395f
Not Applicable
github.com / advisories/GHSA-735f-7qx4-jqq5
Not Applicable
github.com / apple/swift-nio/pull/2419
Patch
github.com / vapor/postgres-nio/commit/2df54bc94607f44584ae6ffa74e3cd754fffafc7
Patch
github.com / vapor/postgres-nio/releases/tag/1.14.2
Release Notes
github.com / vapor/postgres-nio/security/advisories/GHSA-9cfh-vx93-84vv
Vendor Advisory
postgresql.org / support/security/CVE-2021-23214
Not Applicable
postgresql.org / support/security/CVE-2021-23222
Not Applicable