Skip to main content

Vendor/product archive

jackc / pgproto3 CVEs

Beta · best-effort

2 CVEs tagged to jackc / pgproto31 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-32286

Published Mar 26, 2026

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing…

CVSS 7.5 · High
evidence mentions
23
Buzz score
46.0
Vendor/product tagsBeta · best-effort

CVE-2024-27304

Published Mar 6, 2024

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1