Denial of service in github.com/jackc/pgproto3/v2
Summary
| CVE | CVE-2026-32286 |
|---|---|
| State | PUBLISHED |
| Assigner | Go |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-03-26 20:16:12 UTC |
| Updated | 2026-07-22 12:17:33 UTC |
| Description | The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.004940000 probability, percentile 0.394530000 (date 2026-07-22)
Problem Types: CWE-129 | CWE-1285 | CWE-125: Out-of-bounds Read | CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | ADP | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Github.comjackcpgproto3v2 | Github.com/jackc/pgproto3/v2 | unaffected 2.0.0 semver | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 0:165.1-2.el10_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | unaffected 0:165.1-2.el9_8 * rpm | Not specified |
| ADP | Red Hat | Multicluster Global Hub 1.3.4 | unaffected 1779210675 * rpm | Not specified |
| ADP | Red Hat | Multicluster Global Hub 1.3.4 | unaffected 1779210608 * rpm | Not specified |
| ADP | Red Hat | Multicluster Global Hub 1.3.4 | unaffected 1779209992 * rpm | Not specified |
| ADP | Red Hat | Multicluster Global Hub 1.4.5 | unaffected 1779579439 * rpm | Not specified |
| ADP | Red Hat | Multicluster Global Hub 1.5.6 | unaffected 1778867753 * rpm | Not specified |
| ADP | Red Hat | Multicluster Global Hub 1.6.2 | unaffected 1780167118 * rpm | Not specified |
| ADP | Red Hat | Red Hat Advanced Cluster Security 4.8 | unaffected 1777307791 * rpm | Not specified |
| ADP | Red Hat | Red Hat Advanced Cluster Security 4.8 | unaffected 1777307791 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.1 | unaffected 1776736910 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.12 | unaffected 1776752646 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.14 | unaffected 1779689392 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.15 | unaffected 1780891395 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.16 | unaffected 1779204086 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.17 | unaffected 1779922205 * rpm | Not specified |
| ADP | Red Hat | Red Hat Quay 3.9 | unaffected 1776782369 * rpm | Not specified |
| ADP | Red Hat | Assisted Installer For Red Hat OpenShift Container Platform 2 | Not specified | Not specified |
| ADP | Red Hat | Assisted Installer For Red Hat OpenShift Container Platform 2 | Not specified | Not specified |
| ADP | Red Hat | Multicluster Engine For Kubernetes | Not specified | Not specified |
| ADP | Red Hat | Multicluster Engine For Kubernetes | Not specified | Not specified |
| ADP | Red Hat | Multicluster Engine For Kubernetes | Not specified | Not specified |
| ADP | Red Hat | Multicluster Engine For Kubernetes | Not specified | Not specified |
| ADP | Red Hat | Multicluster Engine For Kubernetes | Not specified | Not specified |
| ADP | Red Hat | Multicluster Engine For Kubernetes | Not specified | Not specified |
| ADP | Red Hat | Multicluster Engine For Kubernetes | Not specified | Not specified |
| ADP | Red Hat | Multicluster Engine For Kubernetes | Not specified | Not specified |
| ADP | Red Hat | Multicluster Engine For Kubernetes | Not specified | Not specified |
| ADP | Red Hat | Multicluster Global Hub | Not specified | Not specified |
| ADP | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Advanced Cluster Management For Kubernetes 2 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Advanced Cluster Security 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Advanced Cluster Security 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | Not specified | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift AI RHOAI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Cluster Manager CLI | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift Container Platform 4 | Not specified | Not specified |
| ADP | Red Hat | Red Hat OpenShift On AWS | Not specified | Not specified |
| ADP | Red Hat | Red Hat Quay 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Quay 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Quay 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Quay 3 | Not specified | Not specified |
| ADP | Red Hat | Red Hat Trusted Artifact Signer | Not specified | Not specified |
| ADP | Red Hat | Red Hat Trusted Artifact Signer | Not specified | Not specified |
| ADP | Red Hat | Red Hat Trusted Artifact Signer | Not specified | Not specified |
| ADP | Red Hat | Red Hat Trusted Artifact Signer | Not specified | Not specified |
| ADP | Red Hat | Red Hat Trusted Artifact Signer | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/golang/vulndb/issues/4518 | [email protected] | github.com | Issue Tracking |
| access.redhat.com/errata/RHSA-2026:24853 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:11856 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32286.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:11217 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:21017 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:21769 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| securityinfinity.com/research/memory-safety-vulnerabilities-in-go-postgresql-wire-... | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | securityinfinity.com | Mitigation, Third Party Advisory |
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| github.com/advisories/GHSA-jqcq-xjh3-6g23 | [email protected] | github.com | Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:22450 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:19375 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| pkg.go.dev/vuln/GO-2026-4518 | [email protected] | pkg.go.dev | Patch, Third Party Advisory |
| access.redhat.com/errata/RHSA-2026:23345 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:11070 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:22465 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:11916 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:11996 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| github.com/jackc/pgx/issues/2507 | [email protected] | github.com | Issue Tracking |
| access.redhat.com/errata/RHSA-2026:22347 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-32286 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:22714 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:22423 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-03-26T20:01:59.226Z | Reported to Red Hat. |
| ADP | 2026-03-26T19:40:51.974Z | Made public. |
Solutions
ADP: RHSA-2026:22450: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:22714: Red Hat Enterprise Linux AppStream (v. 9)
ADP: RHSA-2026:22423: Multicluster Global Hub 1.3.4
ADP: RHSA-2026:22347: Multicluster Global Hub 1.4.5
ADP: RHSA-2026:21769: Multicluster Global Hub 1.5.6
ADP: RHSA-2026:23345: Multicluster Global Hub 1.6.2
ADP: RHSA-2026:11070: Red Hat Advanced Cluster Security 4.8
ADP: RHSA-2026:11217: Red Hat Advanced Cluster Security 4.8
ADP: RHSA-2026:11856: Red Hat Quay 3.12
ADP: RHSA-2026:21017: Red Hat Quay 3.14
ADP: RHSA-2026:24853: Red Hat Quay 3.15
ADP: RHSA-2026:19375: Red Hat Quay 3.16
ADP: RHSA-2026:22465: Red Hat Quay 3.17
ADP: RHSA-2026:11916: Red Hat Quay 3.1
ADP: RHSA-2026:11996: Red Hat Quay 3.9
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.