CVE-2026-32286: Jackc PGPROTO3

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

Affected products

  • Jackc PGPROTO3: from 2.0.0, up to and including 2.3.3

Published 2026-03-26. Last modified 2026-09-10.