chore(deps): update module github.com/jackc/pgx/v5 to v5.9.2 [security] #105
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "renovate/go-github.com-jackc-pgx-v5-vulnerability"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
v5.8.0→v5.9.2Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVE-2026-33816 / GHSA-9jj7-4m8r-rfcm / GO-2026-4772
More information
Details
Memory-safety vulnerability in github.com/jackc/pgx/v5.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
CVE-2026-33815 in github.com/jackc/pgx
CVE-2026-33815 / GHSA-xgrm-4fwx-7qm8 / GO-2026-4771
More information
Details
Memory-safety vulnerability in github.com/jackc/pgx/v5.
Severity
Unknown
References
No references.
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
CVE-2026-33816 in github.com/jackc/pgx
CVE-2026-33816 / GHSA-9jj7-4m8r-rfcm / GO-2026-4772
More information
Details
Memory-safety vulnerability in github.com/jackc/pgx/v5.
Severity
Unknown
References
No references.
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
pgx: SQL Injection via placeholder confusion with dollar quoted string literals
CVE-2026-41889 / GHSA-j88v-2chj-qfwx
More information
Details
Impact
SQL Injection can occur when:
e.g.
This is unlikely to occur outside of a contrived scenario.
Patches
The problem is resolved in v5.9.2.
Workarounds
Do not use the simple protocol to execute queries matching all the above conditions.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
jackc/pgx (github.com/jackc/pgx/v5)
v5.9.2Compare Source
v5.9.1Compare Source
v5.9.0Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate.
⚠️ Artifact update problem
Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.
♻ Renovate will retry this branch, including artifacts, only when one of the following happens:
The artifact failure details are included below:
File name: go.sum
View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.