CVE-2026-33815High· 8.3▾ TwilightA flaw was found in github.com/jackc/pgx. This memory-safety vulnerability could potentially lead to unexpected behavior or system instability.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the vendor's CSAF advisory record, not NVD.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.6%
8.3 → 9.8
high → critical
9.8 → 8.3
critical → high
8.3 → 9.8
high → critical
9.8 → 8.3
critical → high
8.3 → 9.8
high → critical
Last analysed / modified upstream
9.8 → 8.3
critical → high
A flaw was found in github.com/jackc/pgx. This memory-safety vulnerability could potentially lead to unexpected behavior or system instability.
github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability — rated Important by Red Hat. Released 2026-04-07, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:41019 You can download the Cryostat 4 on RHEL 9 container images that this update provides from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available in the Red Hat Container Catalog (see the References section).
Dockerfiles and scripts should be amended to refer to this new image specifically or to the latest image generally. https://access.redhat.com/errata/RHSA-2026:17789 See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.0 https://access.redhat.com/errata/RHSA-2026:36796
Workarounds / mitigations:
Affected packages:
github.com/jackc/pgx/v5 < 5.9.0Patched in:
github.com/jackc/pgx/v5 5.9.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-33816High· 8.3github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33816)
CVE-2026-32286High· 7.5The DataRow.Decode function fails to properly validate field lengths
CVE-2026-53488High· 8.8github.com/containerd/containerd: containerd: Host-root command execution via unvalidated image config labels in CRI plugin (CVE-2026-53488)
CVE-2026-32285High· 7.5The Delete function fails to properly validate offsets when processing malformed JSON input
CVE-2026-88839Medium· 6.7BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.
CVE-2026-88832High· 7.3BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.