lib has 7 CVEs on record. Disclosure cadence is accelerating: 7 in the last 90 days against 0 in the 90 before. The busiest recent month was August 2026 with 7. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- —
- Publish → KEV
- —
- Last 90 days
- 7 prev 0
Products
- github.com/lib/pq 7
Worst active — by depth score
CVE-2026-56874NonePre-protocol error reader permits unbounded memory consumption in github.com/lib/pq3CVE-2026-56873NoneBackend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq3CVE-2026-56872NoneMalformed RowDescription and DataRow messages cause panics in github.com/lib/pq3CVE-2026-56871NoneMalformed backend frame length causes panic in github.com/lib/pq3CVE-2026-56870NoneDisclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq3
lib vulnerabilities
CVEs affecting lib, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-56874NonePre-protocol error reader permits unbounded memory consumption in github.com/lib/pq
Pre-protocol error reader permits unbounded memory consumption in github.com/lib/pq
CVE-2026-56873NoneBackend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq
Backend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq
CVE-2026-56872NoneMalformed RowDescription and DataRow messages cause panics in github.com/lib/pq
Malformed RowDescription and DataRow messages cause panics in github.com/lib/pq
CVE-2026-56871NoneMalformed backend frame length causes panic in github.com/lib/pq
Malformed backend frame length causes panic in github.com/lib/pq
CVE-2026-56870NoneDisclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq
Disclosure of wrong .pgpass credential via hostaddr in github.com/lib/pq
CVE-2026-56869NoneUnbounded iteration count causes CPU denial of service in github.com/lib/pq/scram
Unbounded iteration count causes CPU denial of service in github.com/lib/pq/scram
CVE-2026-56868NoneGSS authentication completes without mutual proof in github.com/lib/pq
GSS authentication completes without mutual proof in github.com/lib/pq