---
id: GHSA-3gjw-f78c-vvpw
title: >-
  tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows
  denial of service
summary: >-
  tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows
  denial of service
severity: medium
cwe:
  - CWE-125
vendor: tokio-postgres
product: tokio-postgres
ecosystem: rust
affected:
  - 'tokio-postgres >= 0.4.0, < 0.7.18'
patched:
  - tokio-postgres 0.7.18
published: '2026-08-24'
updated: '2026-08-24'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-3gjw-f78c-vvpw'
references:
  - url: >-
      https://github.com/rust-postgres/rust-postgres/commit/7a00ffa9ad4d951ec0a4564b52f1780fa9d353c1
  - url: >-
      https://github.com/rust-postgres/rust-postgres/releases/tag/tokio-postgres-v0.7.18
  - url: 'https://rustsec.org/advisories/RUSTSEC-2026-0178.html'
  - url: 'https://github.com/advisories/GHSA-3gjw-f78c-vvpw'
tags:
  - ghsa
  - rust
ingestedAt: '2026-08-24T20:10:47.161Z'
---

## Overview

A malicious or compromised server can send a row containing fewer fields than
its row description declares columns. Reading one of the missing columns then
panics with an out-of-bounds index, aborting the calling task. This affects even
the otherwise non-panicking `try_get`, and both `Row` and `SimpleQueryRow`.

Applications that connect only to a trusted database are not exposed; the risk
applies to clients that may connect to untrusted or user-supplied servers, or
whose connection can be intercepted by a man-in-the-middle.

## Affected packages

- `tokio-postgres >= 0.4.0, < 0.7.18`

## Remediation

Upgrade to a patched release:

- `tokio-postgres 0.7.18`
