CVE-2026-32286

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
2
PROJECTS

Description

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

PostgreSQL driver and toolkit for Go
GitHubGitHub
13.9K
[mirror] The Go Vulnerability Database
GitHubGitHub
601