Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqcq-xjh3-6g23

Опубликовано: 18 мар. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Denial of service in github.com/jackc/pgproto3/v2

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

Пакеты

Наименование

github.com/jackc/pgproto3/v2

go
Затронутые версииВерсия исправления

>= 2.0.0, <= 2.3.3

Отсутствует

EPSS

Процентиль: 39%
0.00494
Низкий

7.5 High

CVSS3

Дефекты

CWE-129

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

CVSS3: 7.5
redhat
5 месяцев назад

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

CVSS3: 7.5
nvd
5 месяцев назад

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

CVSS3: 7.5
debian
5 месяцев назад

The DataRow.Decode function fails to properly validate field lengths. ...

rocky
2 месяца назад

Important: osbuild-composer security update

EPSS

Процентиль: 39%
0.00494
Низкий

7.5 High

CVSS3

Дефекты

CWE-129