CVE-2026-56872None▾ SunlitMalformed RowDescription and DataRow messages cause panics in github.com/lib/pq
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
github.com/lib/pq decodes attacker-controlled RowDescription and DataRow payloads without validating their structural relationship or encoded value widths required by binary decoders. A malicious PostgreSQL endpoint or active network attacker on an unauthenticated transport can send malformed row responses, causing unrecovered runtime panics while reading query results.
github.com/lib/pq >= 1.0.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56874NonePre-protocol error reader permits unbounded memory consumption in github.com/lib/pq
CVE-2026-56873NoneBackend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq
CVE-2026-56871NoneMalformed backend frame length causes panic in github.com/lib/pq
CVE-2026-56870NoneDisclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq
CVE-2026-56869NoneUnbounded iteration count causes CPU denial of service in github.com/lib/pq/scram
CVE-2026-56868NoneGSS authentication completes without mutual proof in github.com/lib/pq