CVE-2026-32286

HIGH CVSS 3.1: 7.5 EPSS 0.65%
Updated Sep 10, 2026
Jackc
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions 2.0.0 — 2.3.3
Type CWE-1285, CWE-129 (Improper Validation of Array Index)
Vendor Jackc
Public PoC No

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Jackc Pgproto3
cpe:2.3:a:jackc:pgproto3:*:*:*:*:*:go:*:*
2.0.0 <= 2.3.3

References 23

https://github.com/golang/vulndb/issues/4518
security@golang.org
https://github.com/jackc/pgx/issues/2507
security@golang.org
https://pkg.go.dev/vuln/GO-2026-4518
security@golang.org
https://securityinfinity.com/research/memory-safety-vulnerabilities-in-go-postg…
134c704f-9b21-4f2e-91b3-4a467353bcc0
https://github.com/advisories/GHSA-jqcq-xjh3-6g23
security@golang.org
https://access.redhat.com/errata/RHSA-2026:11070
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:11217
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:11856
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:11916
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:11996
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:19375
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:21017
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:21769
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:22347
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:22423
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:22450
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:22465
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:22714
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:23345
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/errata/RHSA-2026:24853
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://access.redhat.com/security/cve/CVE-2026-32286
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://bugzilla.redhat.com/show_bug.cgi?id=2451847
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32286.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c