---
id: CVE-2026-33816
title: >-
  github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability
  (CVE-2026-33816)
summary: >-
  A flaw was found in github.com/jackc/pgx, a PostgreSQL driver for Go. This
  memory-safety vulnerability could allow an attacker to cause various impacts,
  such as denial of service (DoS) or potentially arbitrary code execution, by
  exploiting…
severity: high
cvss: 8.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'
cvssSource: vendor
cwe:
  - CWE-787
  - CWE-697
vendor: Red Hat
product: Red Hat Openshift Data Foundation 4.20
affected:
  - multicluster_engine_for_kubernetes
  - multicluster_global_hub
  - openshift_pipelines
  - 3scale_api_management_platform 2
  - advanced_cluster_security 4
  - edge_manager 1
  - openshift_ai_rhoai
  - trusted_artifact_signer
  - zero_trust_workload_identity_manager_tech_preview
  - rhem_1_1_for_rhel 10
  - cryostat_4_on_rhel 9
  - rhem_1_0_for_rhel 9
  - rhem_1_1_for_rhel 9
  - enterprise_linux_appstream_v_10
  - custom_metric_autoscaler 2.19
  - multicluster_global_hub 1.3.4
  - multicluster_global_hub 1.7.3
  - advanced_cluster_management_for_kubernetes 2.15
  - advanced_cluster_management_for_kubernetes 2.16
  - advanced_cluster_security 4.8
  - advanced_cluster_security 4.9
  - advanced_cluster_security_for_kubernetes 4.10
  - edge_manager 1.1
  - hardened_images
  - openshift_pipelines 1.21
  - openshift_data_foundation 4.20
  - trusted_artifact_signer 1.3
patched:
  - rhem_1_1_for_rhel 10
  - cryostat_4_on_rhel 9
  - rhem_1_0_for_rhel 9
  - rhem_1_1_for_rhel 9
  - enterprise_linux_appstream_v_10
  - custom_metric_autoscaler 2.19
  - multicluster_global_hub 1.3.4
  - multicluster_global_hub 1.7.3
  - advanced_cluster_management_for_kubernetes 2.15
  - advanced_cluster_management_for_kubernetes 2.16
  - advanced_cluster_security 4.8
  - advanced_cluster_security 4.9
  - advanced_cluster_security_for_kubernetes 4.10
  - edge_manager 1.1
  - hardened_images
  - openshift_pipelines 1.21
  - openshift_data_foundation 4.20
  - trusted_artifact_signer 1.3
published: '2026-04-07'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T16:29:37+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33816.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33816.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-33816'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2455972'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-33816'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-33816'
  - url: 'https://pkg.go.dev/vuln/GO-2026-4772'
  - url: 'https://access.redhat.com/errata/RHSA-2026:41019'
  - url: 'https://access.redhat.com/errata/RHSA-2026:17789'
  - url: 'https://access.redhat.com/errata/RHSA-2026:36796'
  - url: 'https://access.redhat.com/errata/RHSA-2026:19137'
  - url: 'https://access.redhat.com/errata/RHSA-2026:26636'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62866'
  - url: 'https://access.redhat.com/errata/RHSA-2026:22423'
  - url: 'https://access.redhat.com/errata/RHSA-2026:24503'
  - url: 'https://access.redhat.com/errata/RHSA-2026:24539'
  - url: 'https://access.redhat.com/errata/RHSA-2026:25273'
  - url: 'https://access.redhat.com/errata/RHSA-2026:11070'
  - url: 'https://access.redhat.com/errata/RHSA-2026:11217'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13791'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13829'
  - url: 'https://access.redhat.com/errata/RHSA-2026:40945'
  - url: 'https://access.redhat.com/errata/RHSA-2026:40118'
  - url: 'https://access.redhat.com/errata/RHSA-2026:13907'
  - url: 'https://access.redhat.com/errata/RHSA-2026:26519'
  - url: 'https://access.redhat.com/errata/RHSA-2026:40984'
  - url: 'https://access.redhat.com/errata/RHSA-2026:24479'
  - url: 'https://access.redhat.com/errata/RHSA-2026:24475'
  - url: 'https://access.redhat.com/errata/RHSA-2026:24482'
tags:
  - csaf
  - vex
  - red-hat
  - cve.org
  - nvd
  - osv
  - go
epss: 0.00858
epssPercentile: 0.56695
aliases:
  - GO-2026-4772
  - GHSA-9jj7-4m8r-rfcm
ecosystem: go
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-04-09T14:24:50.570972Z'
scores:
  vendor: 8.3
  adp: 9.8
  nvd: 9.8
ingestedAt: '2026-07-09T18:56:37.022Z'
---

## Overview

A flaw was found in github.com/jackc/pgx, a PostgreSQL driver for Go. This memory-safety vulnerability could allow an attacker to cause various impacts, such as denial of service (DoS) or potentially arbitrary code execution, by exploiting memory corruption issues. The exact method of exploitation and specific consequences would depend on the nature of the memory corruption.

## Vendor advisories

- **RHSA-2026:41019** · Red Hat · fixed in: RHEM 1.1 for RHEL 10, RHEM 1.1 for RHEL 9 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41019)
- **RHSA-2026:17789** · Red Hat · fixed in: Cryostat 4 on RHEL 9 · released 2026-05-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:17789)
- **RHSA-2026:36796** · Red Hat · fixed in: RHEM 1.0 for RHEL 9 · released 2026-07-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:36796)
- **RHSA-2026:19137** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19137)
- **RHSA-2026:26636** · Red Hat · fixed in: Custom Metric Autoscaler 2.19 · released 2026-06-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:26636)
- **RHSA-2026:62866** · Red Hat · fixed in: Custom Metric Autoscaler 2.19 · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62866)
- **RHSA-2026:22423** · Red Hat · fixed in: Multicluster Global Hub 1.3.4 · released 2026-06-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:22423)
- **RHSA-2026:24503** · Red Hat · fixed in: Multicluster Global Hub 1.7.3 · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24503)
- **RHSA-2026:24539** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.15 · released 2026-06-08 · [advisory](https://access.redhat.com/errata/RHSA-2026:24539)
- **RHSA-2026:25273** · Red Hat · fixed in: Red Hat Advanced Cluster Management for Kubernetes 2.16 · released 2026-06-11 · [advisory](https://access.redhat.com/errata/RHSA-2026:25273)
- **RHSA-2026:11070** · Red Hat · fixed in: Red Hat Advanced Cluster Security 4.8 · released 2026-04-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:11070)
- **Red Hat VEX** · Important · affected: Multicluster Engine for Kubernetes, Multicluster Global Hub, OpenShift Pipelines, Red Hat 3scale API Management Platform 2, Red Hat Advanced Cluster Security 4, Red Hat Edge Manager 1, … · no fix planned: Red Hat 3scale API Management Platform 2, Zero Trust Workload Identity Manager - Tech Preview, Multicluster Engine for Kubernetes, Multicluster Global Hub, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-33816.json)

**github.com/jackc/pgx/v5: github.com/jackc/pgx: Memory-safety vulnerability** — rated Important by Red Hat. Released 2026-04-07, updated 2026-09-21.

Affected:

- Multicluster Engine for Kubernetes
- Multicluster Global Hub
- OpenShift Pipelines
- Red Hat 3scale API Management Platform 2
- Red Hat Advanced Cluster Security 4
- Red Hat Edge Manager 1
- Red Hat OpenShift AI (RHOAI)
- Red Hat Trusted Artifact Signer
- Zero Trust Workload Identity Manager - Tech Preview

Fixed:

- RHEM 1.1 for RHEL 10
- Cryostat 4 on RHEL 9
- RHEM 1.0 for RHEL 9
- RHEM 1.1 for RHEL 9
- Red Hat Enterprise Linux AppStream (v. 10)
- Custom Metric Autoscaler 2.19
- Multicluster Global Hub 1.3.4
- Multicluster Global Hub 1.7.3
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Advanced Cluster Management for Kubernetes 2.16
- Red Hat Advanced Cluster Security 4.8
- Red Hat Advanced Cluster Security 4.9
- Red Hat Advanced Cluster Security for Kubernetes 4.10
- Red Hat Edge Manager 1.1
- Red Hat Hardened Images
- Red Hat OpenShift Pipelines 1.21
- Red Hat Openshift Data Foundation 4.20
- Red Hat Trusted Artifact Signer 1.3

No fix planned:

- Red Hat 3scale API Management Platform 2
- Zero Trust Workload Identity Manager - Tech Preview
- Multicluster Engine for Kubernetes
- Multicluster Global Hub
- OpenShift Pipelines
- Red Hat Advanced Cluster Security 4
- Red Hat Edge Manager 1
- Red Hat OpenShift AI (RHOAI)
- Red Hat Trusted Artifact Signer

Not affected:

- RHEM 1.1 for RHEL 10
- Cryostat 4 on RHEL 9
- RHEM 1.0 for RHEL 9
- RHEM 1.1 for RHEL 9
- Custom Metric Autoscaler 2.19
- Multicluster Global Hub 1.3.4
- Multicluster Global Hub 1.7.3
- Red Hat Advanced Cluster Management for Kubernetes 2.15
- Red Hat Advanced Cluster Management for Kubernetes 2.16
- Red Hat Advanced Cluster Security 4.8

## Remediation

See the following documentation for details on how to enable Red Hat Edge
Manager and more:
https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.1 https://access.redhat.com/errata/RHSA-2026:41019
You can download the Cryostat 4 on RHEL 9 container images that this update provides from the Red Hat Container Registry at registry.access.redhat.com. Installation instructions for your platform are available in the Red Hat Container Catalog (see the References section).

Dockerfiles and scripts should be amended to refer to this new image specifically or to the latest image generally. https://access.redhat.com/errata/RHSA-2026:17789
See the following documentation for details on how to enable Red Hat Edge Manager and more: https://docs.redhat.com/en/documentation/red_hat_edge_manager/1.0 https://access.redhat.com/errata/RHSA-2026:36796

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2026-33816)

Affected packages:

- `github.com/jackc/pgx/v5 < 5.9.0`

Patched in:

- `github.com/jackc/pgx/v5 5.9.0`

Source: https://osv.dev/vulnerability/GO-2026-4772
