Content Quality: Clear News piece structured per CVE. Body 808 words (808 with link URLs stripped), inside the News range 400-1200. Title 124 characters, under the 150 cap. No internal links, no exploit steps (the advisory's PoC code and reproduction commands are not reproduced), no AI self-reference.
Source Verification: Read all four gunzipped snapshots (source-0..3.html.gz); manifest shows status 200 for all, file non-null, suspicious_patterns null for all four. All four snapshots contain the page body, not just chrome; no live fallback was needed. All three domains (github.com, postgresql.org, raw.githubusercontent.com) are already in config/source_allowlist.txt; no allowlist change. source-0 (GHSA-rhp9-mr79-r74h): title 'requireAuth is silently not enforced when the value excludes every authentication method'; Moderate; CVSS 5.9; CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N; CVE-2026-107314; CWE-636 'Not Failing Securely (Failing Open)'; affected >= 42.7.11, <= 42.7.13; patched 42.7.14; published Oct 7, 2026; publisher shown as sehrope; no Credits section; workaround (positive list, channelBinding=require, sslmode=verify-full); SQLState 08004 and 'Authentication method is not allowed by requireAuth'; root cause AuthMethod.parseRequireAuth/checkAuth null; 'which hides the mistake' is verbatim. All article statements for CVE-2026-107314 confirmed, and the 5.9 in the title attaches to the correct CVE. source-1 (GHSA-f64h-wr5q-3qf3): title 'Driver stores bytes of earlier statements when it pads a value shorter than its declared length' (so 'stored' in the headline is the advisory's own wording, and the server stores the bytes); Moderate; CVSS 5.3; CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N; CVE-2026-107315; CWE-201 and CWE-226; affected >= 42.7.4, <= 42.7.13; patched 42.7.14; published Oct 7, 2026; Credits: vlsi (Finder); 42.7.3 and earlier zero-fill; entry-point list; verbatim 'In each case the driver accepts the call without an error.'; 8192 default send buffer and 'up to maxSendBufferSize bytes'; GSS measurement 'Measured over hostgssenc against PostgreSQL 17.11 with MIT Kerberos from Debian 13 ... stored 16359 non-zero bytes in a 16409-byte padding' appears only in this advisory, as the article says; the fix changes the fill to zeros; 'A correct application, where the declared length always matches the data, is not affected'; 'Values stored by an affected version through such a call can already contain this data.' All confirmed. source-2 (postgresql.org): title '2026-10-07: PostgreSQL JDBC 42.7.14 Security update for multiple CVE's', 'Posted on 2026-10-09 by JDBC Project', quoted phrase 'has released a security release for 2 CVE's' verbatim, lists both CVEs and GHSA IDs. source-3 (CHANGELOG.md at REL42.7.14): top section is still headed '## [Unreleased]', contains only the two requireAuth entries (08004 and 22023), next section is [42.7.13] (2026-07-06); no padding entry. The SQLState 22023 claim is confirmed there ('a requireAuth value without a method in it ... now fails with SQLState 22023') and appears only in that file; the advisory itself says such a value 'is rejected as an invalid requireAuth value' without a code, and the article attributes 22023 to the changelog correctly.
Factual Accuracy: No fabrication found. Project claims are attributed to the advisories and changelog. Credits and CVSS vectors are present in the snapshots (vlsi as Finder on GHSA-f64h; CVSS:3.1 vectors on both) but the article makes no claim about them, so the omission is not an error. The statement 'Neither advisory text read for this article reports exploitation in the wild' is accurate (a search for 'wild' and 'exploit' finds only generic CVSS help text). Date statements are consistent: both advisories 'Oct 7, 2026'; postgresql.org title dated 2026-10-07, 'Posted on 2026-10-09'; the article states the artifact release date is not given in the cited sources. The changelog lag is hedged appropriately ('may simply lag').
Overall Assessment: Accurate, well-sourced security news with the 5.9 and 5.3 scores attached to the correct CVEs, accurate affected ranges, and honest disclosure of the CHANGELOG lag and the single-source GSS measurement. Approved without corrections.