CVE-2026-56869None▾ SunlitUnbounded iteration count causes CPU denial of service in github.com/lib/pq/scram
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The SCRAM client in github.com/lib/pq/scram accepts an attacker-controlled iteration count with no upper bound and immediately performs that many PBKDF2-style HMAC rounds. A PostgreSQL endpoint or active network attacker can send a valid SCRAM server-first message with a large iteration count (such as i=2147483647), causing client authentication to consume excessive CPU resources before verifying the server signature.
github.com/lib/pq >= 1.1.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56874NonePre-protocol error reader permits unbounded memory consumption in github.com/lib/pq
CVE-2026-56873NoneBackend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq
CVE-2026-56872NoneMalformed RowDescription and DataRow messages cause panics in github.com/lib/pq
CVE-2026-56871NoneMalformed backend frame length causes panic in github.com/lib/pq
CVE-2026-56870NoneDisclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq
CVE-2026-56868NoneGSS authentication completes without mutual proof in github.com/lib/pq