blob: c258a1665129369b07c8bb6dab2453f085a21e9f [file]
{
"schema_version": "1.3.1",
"id": "GO-2026-5004",
"modified": "0001-01-01T00:00:00Z",
"published": "0001-01-01T00:00:00Z",
"aliases": [
"CVE-2026-41889",
"GHSA-j88v-2chj-qfwx"
],
"summary": "SQL Injection via placeholder confusion with dollar quoted string literals in github.com/jackc/pgx",
"details": "SQL Injection can occur when using the non-default simple protocol with a dollar quoted string literal in the SQL query. If that string literal contains text that would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker, an injection may be possible.\n\nFor example, an attacker could provide a value that includes a closing dollar quote followed by malicious SQL commands. This is unlikely to occur outside of a contrived scenario.",
"affected": [
{
"package": {
"name": "github.com/jackc/pgx",
"ecosystem": "Go"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"ecosystem_specific": {
"imports": [
{
"path": "github.com/jackc/pgx/internal/sanitize",
"symbols": [
"Query.Sanitize",
"SanitizeSQL"
]
}
]
}
},
{
"package": {
"name": "github.com/jackc/pgx/v4",
"ecosystem": "Go"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
}
]
}
],
"ecosystem_specific": {
"imports": [
{
"path": "github.com/jackc/pgx/v4/internal/sanitize",
"symbols": [
"Query.Sanitize",
"SanitizeSQL"
]
}
]
}
},
{
"package": {
"name": "github.com/jackc/pgx/v5",
"ecosystem": "Go"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "0"
},
{
"fixed": "5.9.2"
}
]
}
],
"ecosystem_specific": {
"imports": [
{
"path": "github.com/jackc/pgx/v5/internal/sanitize",
"symbols": [
"Query.Sanitize",
"SanitizeSQL"
]
}
]
}
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://github.com/jackc/pgx/security/advisories/GHSA-j88v-2chj-qfwx"
},
{
"type": "FIX",
"url": "https://github.com/jackc/pgx/commit/60644f84918a8af66d14a4b0d865d4edafd955da"
},
{
"type": "WEB",
"url": "https://github.com/jackc/pgx/releases/tag/v5.9.2"
}
],
"credits": [
{
"name": "Jack Christensen"
}
],
"database_specific": {
"url": "https://pkg.go.dev/vuln/GO-2026-5004",
"review_status": "REVIEWED"
}
}