github.com/jackc/pgx/v5
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/jackc/pgx/v5page 1 of 1
- CVE-2024-27304CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.5.42024-03-06
pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be…
- CVE-2026-33815CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.9.02026-04-07
Memory-safety vulnerability in github.com/jackc/pgx/v5.
- CVE-2026-33816CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.9.02026-04-07
Memory-safety vulnerability in github.com/jackc/pgx/v5.
- CVE-2026-41889CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.9.22026-05-08
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that wo…
Check whether github.com/jackc/pgx/v5 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/jackc/pgx/v5 CVEs against the assets you own.
Start Free Scan →