PT-2026-37159 · Pgx · Pgx

·

CVE-2026-41889

·

Published

2026-04-22

·

Updated

2026-07-30

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pgx versions prior to 5.9.2
Description SQL injection can occur when the non-default simple protocol is used in conjunction with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal and the value of that placeholder is controllable by an attacker, the issue can be exploited.
Recommendations Update to version 5.9.2. As a temporary workaround, do not use the simple protocol to execute queries that utilize dollar quoted string literals containing potential placeholders.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-86322
AZL-86325
CLEANSTART-2026-AP95632
CLEANSTART-2026-CN27900
CLEANSTART-2026-GR41888
CLEANSTART-2026-GZ11549
CLEANSTART-2026-IM39799
CLEANSTART-2026-KJ73757
CLEANSTART-2026-LY44407
CLEANSTART-2026-NT30039
CLEANSTART-2026-QS87161
CLEANSTART-2026-SP73148
CLEANSTART-2026-UV44486
CLEANSTART-2026-YG71543
CLEANSTART-2026-ZF00349
CLEANSTART-2026-ZN45188
CVE-2026-41889
GHSA-J88V-2CHJ-QFWX
GO-2026-5004
OPENSUSE-SU-2026:10976-1
OPENSUSE-SU-2026:10992-1
OPENSUSE-SU-2026:21251-1
OPENSUSE-SU-2026:21483-1
RHSA-2026:15856
RHSA-2026:16133
RHSA-2026:25138
SUSE-SU-2026:22575-1
SUSE-SU-2026:2824-1

Affected Products

Pgx