CVE-2026-32286

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jackc:pgproto3:*:*:*:*:*:go:*:*

History

No history.

Information

Published : 2026-03-26 20:16

Updated : 2026-09-10 13:18


NVD link : CVE-2026-32286

Mitre link : CVE-2026-32286

CVE.ORG link : CVE-2026-32286


JSON object : View

Products Affected

jackc

  • pgproto3
CWE
CWE-129

Improper Validation of Array Index

CWE-1285

Improper Validation of Specified Index, Position, or Offset in Input