PT-2026-80409 · Go · Github.Com/Lib/Pq

Published

2026-08-18

·

Updated

2026-08-18

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
(This report has been withdrawn with reason: "Report mistakenly added without having CVE / GHSA associated"). When a connection specifies hostaddr without host, github.com/lib/pq dials the numeric hostaddr but performs .pgpass lookup using the default Config.Host value, localhost. If the passfile contains different credentials for localhost and the remote address, the driver selects the secret intended for the local database and sends it to the remote endpoint when that endpoint requests password authentication.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GO-2026-6169

Affected Products

Github.Com/Lib/Pq