---
id: CVE-2026-32286
title: The DataRow.Decode function fails to properly validate field lengths
summary: >-
  The DataRow.Decode function fails to properly validate field lengths. A
  malicious or compromised PostgreSQL server can send a DataRow message with a
  negative field length, causing a slice bounds out of range panic.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-129
  - CWE-1285
  - CWE-125
vendor: jackc
product: pgproto3
affected:
  - 'pgproto3 >= 2.0.0, <= 2.3.3'
patched:
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_9
  - multicluster_global_hub 1.3.4
  - multicluster_global_hub 1.4.5
  - multicluster_global_hub 1.6.5
  - advanced_cluster_security 4.8
  - quay 3.12
  - quay 3.14
  - quay 3.15
  - quay 3.16
  - quay 3.17
  - quay 3.1
  - quay 3.9
  - multicluster_global_hub 1.5.3
published: '2026-03-26'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:18:08.907'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-32286'
references:
  - url: 'https://github.com/advisories/GHSA-jqcq-xjh3-6g23'
    label: security@golang.org
  - url: 'https://github.com/golang/vulndb/issues/4518'
    label: security@golang.org
  - url: 'https://github.com/jackc/pgx/issues/2507'
    label: security@golang.org
  - url: 'https://pkg.go.dev/vuln/GO-2026-4518'
    label: security@golang.org
  - url: 'https://access.redhat.com/errata/RHSA-2026:11070'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11217'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11856'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11916'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:11996'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19375'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21017'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21769'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22347'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22423'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22450'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22465'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22714'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:23345'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24853'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-32286'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2451847'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32286.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://securityinfinity.com/research/memory-safety-vulnerabilities-in-go-postgresql-wire-protocol-parsers-pgproto3-pgx
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-32286'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-32286'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-03-30T14:08:15.986882Z'
epss: 0.0065
epssPercentile: 0.49784
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/moisei-dev/go-dbmigrate'
    - 'https://github.com/slashid/baton-retool'
  checkedAt: '2026-09-24T07:53:02.078Z'
ingestedAt: '2026-07-01T15:50:58.741Z'
---

## Overview

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

## Affected

- `pgproto3 >= 2.0.0, <= 2.3.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:22450** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-06-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:22450)
- **RHSA-2026:22714** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-06-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:22714)
- **RHSA-2026:22423** · Red Hat · fixed in: Multicluster Global Hub 1.3.4 · released 2026-06-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:22423)
- **RHSA-2026:22347** · Red Hat · fixed in: Multicluster Global Hub 1.4.5 · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22347)
- **RHSA-2026:23345** · Red Hat · fixed in: Multicluster Global Hub 1.6.5 · released 2026-06-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:23345)
- **RHSA-2026:11070** · Red Hat · fixed in: Red Hat Advanced Cluster Security 4.8 · released 2026-04-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:11070)
- **RHSA-2026:11217** · Red Hat · fixed in: Red Hat Advanced Cluster Security 4.8 · released 2026-04-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:11217)
- **RHSA-2026:11856** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-04-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:11856)
- **RHSA-2026:21017** · Red Hat · fixed in: Red Hat Quay 3.14 · released 2026-05-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:21017)
- **RHSA-2026:24853** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-06-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:24853)
- **RHSA-2026:19375** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19375)
- **Red Hat VEX** · Important · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Multicluster Engine for Kubernetes, Red Hat Advanced Cluster Management for Kubernetes 2, Red Hat Enterprise Linux 8, Red Hat OpenShift AI (RHOAI), Red Hat OpenShift Cluster Manager CLI, … · no fix planned: Red Hat Enterprise Linux 8, Red Hat Quay 3, Assisted Installer for Red Hat OpenShift Container Platform 2, Multicluster Engine for Kubernetes, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32286.json)
- **RHSA-2026:11916** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-04-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:11916)
