CVE-2017-16082: Node-Postgres Pg

Critical severity, CVSS 9.8. EPSS: 10.5% chance of exploitation in the next 30 days.

A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) Executing unsafe, user-supplied sql which contains a malicious column name. 2) Connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

Affected products

  • Node-Postgres Pg: from 2.0.0, before 2.11.2 (fixed in 2.11.2); from 3.0.0, before 3.6.4 (fixed in 3.6.4); from 4.0.0, before 4.5.7 (fixed in 4.5.7); after 5.0.0, before 5.2.1 (fixed in 5.2.1); from 6.0.0, before 6.4.2 (fixed in 6.4.2); from 7.0.0, before 7.1.2 (fixed in 7.1.2)

Published 2018-06-07. Last modified 2026-06-17.