github.com/jackc/pgproto3/v2 vulnerability

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

Published 26 Mar 2026Updated 7 Sep 202623 sources
CVSS 7.5

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.