github.com/jackc/pgproto3/v2
Activity
- Latest release
- 2y ago
- Total releases
- 18
- Cadence
- ~2 months
- Last 12 months
- 0
Reach
- Stars
- —
Details
- First release
- Aug 28, 2019
| Version | Released | |
|---|---|---|
v2.3.3
patch
1 CVE
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev |
v2.3.3
patch
Dependencies (3)
|
|
v2.3.2
patch
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.3.2
patch
Dependencies (3)
|
|
v2.3.1
patch
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.3.1
patch
Dependencies (3)
|
|
v2.3.0
minor
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.3.0
minor
Dependencies (3)
|
|
v2.2.0
minor
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.2.0
minor
Dependencies (3)
|
|
v2.1.1
patch
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.1.1
patch
Dependencies (3)
|
|
v2.1.0
minor
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.1.0
minor
Dependencies (3)
|
|
v2.0.7
patch
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.7
patch
Dependencies (3)
|
|
v2.0.6
patch
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.6
patch
Dependencies (3)
|
|
v2.0.5
patch
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.5
patch
Dependencies (3)
|
|
v2.0.4
patch
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.4
patch
Dependencies (3)
|
|
v2.0.3
patch
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.3
patch
Dependencies (3)
|
|
v2.0.2
patch
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.2
patch
Dependencies (3)
|
|
v2.0.1
patch
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.1
patch
Dependencies (3)
|
|
v2.0.0
initial
2 CVEs
CVE-2026-32286
GHSA-jqcq-xjh3-6g23
GO-2026-4518
Mar 18, 2026
Denial of service in github.com/jackc/pgproto3/v2
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.0
initial
Dependencies (2)
|
|
v2.0.0-rc3
pre
1 CVE
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.0-rc3
pre
Dependencies (2)
|
|
v2.0.0-rc2
pre
1 CVE
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.0-rc2
pre
Dependencies (4)
|
|
v2.0.0-rc1
pre
1 CVE
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
2.3.3
References
Updated Feb 04, 2026 · Source: OSV.dev |
v2.0.0-rc1
pre
Dependencies (4)
|