PT-2026-80409 · Go · Github.Com/Lib/Pq

Publicado

2026-08-18

·

Atualizado

2026-08-18

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
(This report has been withdrawn with reason: "Report mistakenly added without having CVE / GHSA associated"). When a connection specifies hostaddr without host, github.com/lib/pq dials the numeric hostaddr but performs .pgpass lookup using the default Config.Host value, localhost. If the passfile contains different credentials for localhost and the remote address, the driver selects the secret intended for the local database and sends it to the remote endpoint when that endpoint requests password authentication.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

GO-2026-6169

Produtos afetados

Github.Com/Lib/Pq