CVE-2026-32286: Jackc PGPROTO3
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.
Affected products
- Jackc PGPROTO3: from 2.0.0, up to and including 2.3.3
Published 2026-03-26. Last modified 2026-09-10.