CVE-2026-56871None▾ SunlitMalformed backend frame length causes panic in github.com/lib/pq
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
github.com/lib/pq trusts the unsigned 32-bit length in every PostgreSQL backend frame and subtracts four without first checking that the wire length is at least four. A backend frame whose length is zero through three produces a negative payload length. recvMessage then slices the connection scratch buffer with that negative bound, causing an unrecovered runtime panic that terminates the calling goroutine and process.
github.com/lib/pq >= 1.0.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56874NonePre-protocol error reader permits unbounded memory consumption in github.com/lib/pq
CVE-2026-56873NoneBackend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq
CVE-2026-56872NoneMalformed RowDescription and DataRow messages cause panics in github.com/lib/pq
CVE-2026-56870NoneDisclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq
CVE-2026-56869NoneUnbounded iteration count causes CPU denial of service in github.com/lib/pq/scram
CVE-2026-56868NoneGSS authentication completes without mutual proof in github.com/lib/pq