Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jqcq-xjh3-6g23 | Denial of service in github.com/jackc/pgproto3/v2 |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 30 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Sat, 28 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1285 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 27 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Fri, 27 Mar 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jackc
Jackc pgproto3 |
|
| Vendors & Products |
Jackc
Jackc pgproto3 |
Thu, 26 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic. | |
| Title | Denial of service in github.com/jackc/pgproto3/v2 | |
| References |
|
Status: PUBLISHED
Assigner: Go
Published:
Updated: 2026-04-02T19:08:53.981Z
Reserved: 2026-03-11T16:38:46.556Z
Link: CVE-2026-32286
Updated: 2026-03-30T14:08:56.643Z
Status : Undergoing Analysis
Published: 2026-03-26T20:16:12.303
Modified: 2026-04-02T20:16:23.443
Link: CVE-2026-32286
OpenCVE Enrichment
Updated: 2026-03-29T20:27:51Z
Github GHSA