PT-2026-80413 · Go · Github.Com/Lib/Pq

Publicado

2026-08-18

·

Atualizado

2026-08-18

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
(This report has been withdrawn with reason: "Report mistakenly added without having CVE / GHSA associated"). The special-case parser for PostgreSQL pre-protocol plain-text errors in github.com/lib/pq calls bufio.Reader.ReadString(0) without a byte limit. A malicious PostgreSQL endpoint or active network attacker on an unauthenticated transport can send an error message response with non-NUL bytes continuously, causing the client to buffer an arbitrarily large string and crash with an unrecoverable out-of-memory error.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

GO-2026-6173

Produtos afetados

Github.Com/Lib/Pq