Skip to main content

Vendor archive

jackc CVEs

Beta · best-effort

6 CVEs tagged to vendor jackc3 Critical, 2 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2026-41889

Published May 8, 2026

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used…

CVSS 2.3 · Low
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-33816

Published Apr 7, 2026

Memory-safety vulnerability in github.com/jackc/pgx/v5.

CVSS 9.8 · Critical
evidence mentions
25
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-33815

Published Apr 7, 2026

Memory-safety vulnerability in github.com/jackc/pgx/v5.

CVSS 9.8 · Critical
evidence mentions
20
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-32286

Published Mar 26, 2026

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing…

CVSS 7.5 · High
evidence mentions
23
Buzz score
46.0
Vendor/product tagsBeta · best-effort

CVE-2024-27304

Published Mar 6, 2024

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-27289

Published Mar 6, 2024

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is us…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1