CVE-2026-56870None▾ SunlitDisclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
When a connection specifies hostaddr without host, github.com/lib/pq dials the numeric hostaddr but performs .pgpass lookup using the default Config.Host value, localhost. If the passfile contains different credentials for localhost and the remote address, the driver selects the secret intended for the local database and sends it to the remote endpoint when that endpoint requests password authentication.
github.com/lib/pq >= 1.11.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56874NonePre-protocol error reader permits unbounded memory consumption in github.com/lib/pq
CVE-2026-56873NoneBackend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq
CVE-2026-56872NoneMalformed RowDescription and DataRow messages cause panics in github.com/lib/pq
CVE-2026-56871NoneMalformed backend frame length causes panic in github.com/lib/pq
CVE-2026-56869NoneUnbounded iteration count causes CPU denial of service in github.com/lib/pq/scram
CVE-2026-56868NoneGSS authentication completes without mutual proof in github.com/lib/pq