github.com/jackc/pgx/v5
PostgreSQL driver and toolkit for Go
Activity
- Latest release
- 6d ago
- Total releases
- 44
- Cadence
- ~21 days
- Last 12 months
- 6
Reach
- Stars
- 14.2k
Details
- First release
- Mar 19, 2022
| Version | Released | |
|---|---|---|
v5.11.0
minor
|
v5.11.0
minor
Dependencies (6)
|
|
v5.10.0
minor
|
v5.10.0
minor
Dependencies (6)
|
|
v5.9.2
patch
|
v5.9.2
patch
Dependencies (6)
|
|
v5.9.1
patch
1 CVE
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev |
v5.9.1
patch
Dependencies (6)
|
|
v5.9.0
minor
1 CVE
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev |
v5.9.0
minor
Dependencies (6)
|
|
v5.8.0
minor
3 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.8.0
minor
Dependencies (6)
|
|
v5.7.6
patch
3 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.7.6
patch
Dependencies (7)
|
|
v5.7.5
patch
3 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.7.5
patch
Dependencies (7)
|
|
v5.7.4
patch
3 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.7.4
patch
Dependencies (7)
|
|
v5.7.3
patch
3 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.7.3
patch
Dependencies (7)
|
|
v5.7.2
patch
3 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.7.2
patch
Dependencies (7)
|
|
v5.7.1
patch
3 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.7.1
patch
Dependencies (7)
|
|
v5.7.0
minor
3 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.7.0
minor
Dependencies (6)
|
|
v5.6.0
minor
3 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.6.0
minor
Dependencies (6)
|
|
v5.5.5
patch
3 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.5.5
patch
Dependencies (6)
|
|
v5.5.4
patch
3 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.5.4
patch
Dependencies (6)
|
|
v5.5.3
patch
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.5.3
patch
Dependencies (6)
|
|
v5.5.2
patch
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.5.2
patch
Dependencies (6)
|
|
v5.5.1
patch
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.5.1
patch
Dependencies (6)
|
|
v5.5.0
minor
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.5.0
minor
Dependencies (6)
|
|
v5.4.3
patch
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.4.3
patch
Dependencies (6)
|
|
v5.4.2
patch
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.4.2
patch
Dependencies (7)
|
|
v5.4.1
patch
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.4.1
patch
Dependencies (7)
|
|
v5.4.0
minor
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.4.0
minor
Dependencies (7)
|
|
v5.3.1
patch
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.3.1
patch
Dependencies (6)
|
|
v5.3.0
minor
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.3.0
minor
Dependencies (6)
|
|
v5.2.0
minor
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.2.0
minor
Dependencies (6)
|
|
v5.1.1
patch
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.1.1
patch
Dependencies (6)
|
|
v5.1.0
minor
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.1.0
minor
Dependencies (6)
|
|
v5.0.4
patch
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.0.4
patch
Dependencies (6)
|
|
v5.0.3
patch
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.0.3
patch
Dependencies (6)
|
|
v5.0.2
patch
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.0.2
patch
Dependencies (6)
|
|
v5.0.1
patch
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.0.1
patch
Dependencies (6)
|
|
v5.0.0
initial
5 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev
CVE-2024-27304
GO-2024-2606
GHSA-7jwh-3vrq-q3m8
GHSA-mrww-27vc-gghv
Mar 14, 2024
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size. Fixed in
5.5.4
References
Updated Feb 04, 2026 · Source: OSV.dev |
v5.0.0
initial
Dependencies (6)
|
|
v5.0.0-beta.5
pre
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev |
v5.0.0-beta.5
pre
Dependencies (6)
|
|
v5.0.0-beta.4
pre
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev |
v5.0.0-beta.4
pre
Dependencies (6)
|
|
v5.0.0-beta.3
pre
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev |
v5.0.0-beta.3
pre
Dependencies (6)
|
|
v5.0.0-beta.2
pre
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev |
v5.0.0-beta.2
pre
Dependencies (6)
|
|
v5.0.0-beta.1
pre
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev |
v5.0.0-beta.1
pre
Dependencies (6)
|
|
v5.0.0-alpha.5
pre
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev |
v5.0.0-alpha.5
pre
Dependencies (6)
|
|
v5.0.0-alpha.4
pre
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev |
v5.0.0-alpha.4
pre
Dependencies (6)
|
|
v5.0.0-alpha.3
pre
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev |
v5.0.0-alpha.3
pre
Dependencies (6)
|
|
v5.0.0-alpha.2
pre
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev |
v5.0.0-alpha.2
pre
Dependencies (6)
|
|
v5.0.0-alpha.1
pre
4 CVEs
CVE-2026-41889
GO-2026-5004
GHSA-j88v-2chj-qfwx
Jun 22, 2026
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible. For example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario. Fixed in
5.9.2
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-33815
GHSA-xgrm-4fwx-7qm8
GO-2026-4771
Apr 07, 2026
pgx contains memory-safety vulnerability
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
pgx is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-33816
GHSA-9jj7-4m8r-rfcm
GO-2026-4772
Apr 07, 2026
Memory-safety vulnerability in github.com/jackc/pgx/v5.
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
Memory-safety vulnerability in github.com/jackc/pgx/v5. Fixed in
5.9.0
References Updated Sep 10, 2026 · Source: OSV.dev
GHSA-fqpg-rq76-99pq
GO-2024-2567
Jul 05, 2024
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
Pipeline can panic when PgConn is busy or closed. Fixed in
5.5.2
References Updated Mar 19, 2026 · Source: OSV.dev |
v5.0.0-alpha.1
pre
Dependencies (6)
|