CVE-2026-33816High· 8.3▾ TwilightA flaw was found in github.com/jackc/pgx, a PostgreSQL driver for Go. This memory-safety vulnerability could allow an attacker to cause various impacts, such as denial of service (DoS) or potentially arbitrary code execution, by exploiting…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the vendor's CSAF advisory record, not NVD.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
0.6%
— → 9.8
none → critical
9.8 → —
critical → none
— → 9.8
none → critical
9.8 → —
critical → none
— → 9.8
none → critical
Last analysed / modified upstream
9.8 → 8.3
critical → high
A flaw was found in github.com/jackc/pgx, a PostgreSQL driver for Go. This memory-safety vulnerability could allow an attacker to cause various impacts, such as denial of service (DoS) or potentially arbitrary code execution, by exploiting memory corruption issues. The exact method of exploitation and specific consequences would depend on the nature of the memory corruption.
github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability — rated Important by Red Hat. Released 2026-04-07, updated 2026-09-21.
Affected:
Fixed:
No fix planned:
Not affected:
See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:41019 You can download the Cryostat 4 on RHEL 9 container images that this update provides from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available in the Red Hat Container Catalog (see the References section).
Dockerfiles and scripts should be amended to refer to this new image specifically or to the latest image generally. https://access.redhat.com/errata/RHSA-2026:17789 See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.0 https://access.redhat.com/errata/RHSA-2026:36796
Workarounds / mitigations:
Affected packages:
github.com/jackc/pgx/v5 < 5.9.0Patched in:
github.com/jackc/pgx/v5 5.9.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-33815High· 8.3github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability (CVE-2026-33815)
CVE-2026-91142Low· 3.6A flaw was found in Cockpit
CVE-2026-81627High· 8.2A flaw was found in QEMU
CVE-2026-90949High· 7.8A flaw was found in GIMP's PSP (Paint Shop Pro) file loader
CVE-2026-90948High· 7.8A flaw was found in GIMP's ICO file loader
CVE-2026-6734High· 7.5undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734)