← Back

CVE-2024-27304

nvd nist
Published: Mar 6, 2024Modified: May 21, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: security-advisories@github.com (Secondary)

Description

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

Affected (3)

Products: Jackc: Pgproto3, Pgx
2 products
Pgproto3
Pgx
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.3.3
Jackc
Before 4.18.2
From 5.0.0 to 5.5.4

References (13)

Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Press/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.