GHSA-rgqc-3x5p-6gwgMedium▾ Sunlitpostgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A malicious or compromised server can return a binary hstore value with an
invalid internal length field, causing the client to panic while decoding it.
Applications that connect only to a trusted database are not exposed; the risk applies to clients that may connect to untrusted or user-supplied servers, or whose connection can be intercepted by a man-in-the-middle.
postgres-protocol < 0.6.12Upgrade to a patched release:
postgres-protocol 0.6.12Connected by shared product, vendor, weakness, or advisory.
RUSTSEC-2026-0180NonePanic decoding a malformed `hstore` value allows denial of service
GHSA-5x78-73v4-xg6wHighpostgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
RUSTSEC-2026-0179NoneUnbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2020-3478High· 8.1A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to overwrite certain files that should be restricted on an affected device
CVE-2020-3577High· 7.4A vulnerability in the ingress packet processing path of Cisco Firepower Threat Defense (FTD) Software for interfaces that are configured either as Inline Pair or in Passive mode could allow an unauthenticated, adjacent attacker to cause…