Description
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for a numeric value must be immediately preceded by a minus; there must be a second placeholder for a string value after the first placeholder; both must be on the same line; and both parameter values must be user-controlled. The problem is resolved in v4.18.2. As a workaround, do not use the simple protocol or do not place a minus directly before a placeholder.
Published: 2024-03-06
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-0962 pgx SQL Injection via Line Comment Creation
Github GHSA Github GHSA GHSA-m7wr-2xf7-cm9p pgx SQL Injection via Line Comment Creation
History

Thu, 11 Dec 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Pgx Project
Pgx Project pgx
CPEs cpe:2.3:a:sgx_project:sgx:*:*:*:*:*:go:*:* cpe:2.3:a:pgx_project:pgx:*:*:*:*:*:go:*:*
Vendors & Products Sgx Project
Sgx Project sgx
Pgx Project
Pgx Project pgx

Thu, 04 Dec 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Sgx Project
Sgx Project sgx
CPEs cpe:2.3:a:sgx_project:sgx:*:*:*:*:*:go:*:*
Vendors & Products Sgx Project
Sgx Project sgx

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00092}

epss

{'score': 0.00095}


Thu, 12 Jun 2025 16:30:00 +0000


Wed, 16 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Jackc
Jackc pgx
CPEs cpe:2.3:a:jackc:pgx:*:*:*:*:*:*:*:*
Vendors & Products Jackc
Jackc pgx
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Oct 2024 02:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.16::el9

Wed, 16 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift
CPEs cpe:/a:redhat:openshift:4.17::el9
Vendors & Products Redhat openshift

Subscriptions

Jackc Pgx
Pgx Project Pgx
Redhat Advanced Cluster Security Openshift
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-06-12T15:45:56.361Z

Reserved: 2024-02-22T18:08:38.873Z

Link: CVE-2024-27289

cve-icon Vulnrichment

Updated: 2025-06-12T15:45:56.361Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-06T19:15:08.140

Modified: 2025-12-11T15:45:33.937

Link: CVE-2024-27289

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-03-07T00:00:00Z

Links: CVE-2024-27289 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses