github.com/jackc/pgx/v5 known bugs

go

7 known bugs in github.com/jackc/pgx/v5, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.

7
bugs
Known bugs
SeverityAffectedFixed inTitleStatusSource
highany4.18.2
pgx SQL Injection via Protocol Message Size Overflow
### Impact SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. ### Patches The problem is resolved in v4.18.2 and v5.5.4. ### Workarounds Reject user input large enough to cause a single query or bind message to exceed 4 GB in size.
fixedosv:GHSA-mrww-27vc-gghv
mediumany5.9.0
CVE-2026-33816 in github.com/jackc/pgx
Memory-safety vulnerability in github.com/jackc/pgx/v5.
fixedosv:GO-2026-4772
mediumany5.9.0
CVE-2026-33815 in github.com/jackc/pgx
Memory-safety vulnerability in github.com/jackc/pgx/v5.
fixedosv:GO-2026-4771
mediumany2.3.3
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx
An integer overflow in the calculated message size of a query or bind message could allow a single large message to be sent as multiple messages under the attacker's control. This could lead to SQL injection if an attacker can cause a single query or bind message to exceed 4 GB in size.
fixedosv:GO-2024-2606
medium5.0.0-alpha.55.5.2
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
Pipeline can panic when PgConn is busy or closed.
fixedosv:GO-2024-2567
mediumany5.5.2
Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx
Pipeline can panic when PgConn is busy or closed.
fixedosv:GHSA-fqpg-rq76-99pq
criticalany5.9.0
Memory-safety vulnerability in github.com/jackc/pgx/v5.
Memory-safety vulnerability in github.com/jackc/pgx/v5.
fixedosv:GHSA-9jj7-4m8r-rfcm
API access

Get this data programmatically \u2014 free, no authentication.

curl https://depscope.dev/api/bugs/go/github.com/jackc/pgx/v5
github.com/jackc/pgx/v5 bugs — known issues per version | DepScope | DepScope