Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41889

Опубликовано: 08 мая 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker. This issue has been patched in version 5.9.2.

A flaw was found in pgx, a PostgreSQL driver and toolkit for Go. This SQL injection vulnerability can occur when using the non-default simple protocol, a dollar-quoted string literal in the SQL query, and when that string literal contains text interpreted as a placeholder with an attacker-controlled value. An attacker could potentially manipulate SQL queries, leading to a low impact on data integrity.

Отчет

Red Hat has rated this flaw as Moderate because the SQL injection vulnerability in pgx can only be triggered when the non-default simple protocol is used in conjunction with specific query constructions involving PostgreSQL dollar-quoted string literals. Successful exploitation requires multiple uncommon preconditions, including attacker control of placeholder values within affected queries. As the issue is limited to particular application usage patterns and does not affect default pgx configurations, the overall risk is reduced despite the potential for query manipulation in vulnerable applications.The strongest argument for a Moderate rating is that this is not a generic SQL injection affecting all pgx users; it is a narrowly scoped flaw requiring a non-default mode and specific application behavior

Меры по смягчению последствий

Avoid using the non-default simple protocol in applications that use the pgx PostgreSQL driver for Go. The vulnerability is contingent on this non-default protocol and specific SQL query constructs. Configuring applications to use the default extended protocol prevents this issue. If the simple protocol is necessary, ensure that dollar-quoted string literals do not contain attacker-controlled placeholder values.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-agent-rhel9Fix deferred
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-controller-rhel9Fix deferred
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-rhel9Fix deferred
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9Fix deferred
Custom Metric Autoscaler operator for Red Hat Openshiftcustom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operatorFix deferred
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-agent-rhel8Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/assisted-installer-agent-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2468307github.com/jackc/pgx: golang: pgx: SQL injection via specific SQL query conditions

EPSS

Процентиль: 28%
0.00356
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker. This issue has been patched in version 5.9.2.

CVSS3: 9.8
nvd
3 месяца назад

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker. This issue has been patched in version 5.9.2.

msrc
3 месяца назад

pgx: SQL Injection via placeholder confusion with dollar quoted string literals

CVSS3: 9.8
debian
3 месяца назад

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, ...

github
4 месяца назад

pgx: SQL Injection via placeholder confusion with dollar quoted string literals

EPSS

Процентиль: 28%
0.00356
Низкий

5.9 Medium

CVSS3