CVE-2026-32286
EUVD-2026-1634726.03.2026, 20:16
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| jackc | pgproto3 | 2.0.0 ≤ 𝑥 ≤ 2.3.3 |
𝑥
= Vulnerable software versions
Red Hat Enterprise Linux Releases