6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/jackc/pgx/v4 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-41889
pgx: SQL Injection via placeholder confusion with dollar quoted string literals
CRITICAL 9.8
CVE-2024-27304
pgx SQL Injection via Protocol Message Size Overflow
HIGH 8.1
CVE-2024-27289
pgx SQL Injection via Line Comment Creation
UNKNOWN
CVE-2026-41889
SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx
UNKNOWN
CVE-2024-27304
SQL injection in github.com/jackc/pgproto3 and github.com/jackc/pgx
UNKNOWN
CVE-2024-27289
SQL injection in github.com/jackc/pgx/v4
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes