HIGH 7.5 Go

Duplicate Advisory: pgproto3: Negative field length panics in DataRow.Decode

GHSA-x6gf-mpr2-68h6 · CVE-2026-4427

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-jqcq-xjh3-6g23. This link is maintained to preserve external references.

Original Description

A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.

Ready to move

Start Securing

Free, no credit card | First findings in minutes