blob: ecf0953d613fd73a6c3d02f47a06b0b23d952a98 [file] [edit]
{
"schema_version": "1.3.1",
"id": "GO-2026-6173",
"modified": "0001-01-01T00:00:00Z",
"published": "0001-01-01T00:00:00Z",
"withdrawn": "2026-08-18T20:23:02Z",
"aliases": [
"CVE-2026-56874"
],
"summary": "WITHDRAWN: Pre-protocol error reader permits unbounded memory consumption in github.com/lib/pq",
"details": "(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). The special-case parser for PostgreSQL pre-protocol plain-text errors in github.com/lib/pq calls bufio.Reader.ReadString(0) without a byte limit. A malicious PostgreSQL endpoint or active network attacker on an unauthenticated transport can send an error message response with non-NUL bytes continuously, causing the client to buffer an arbitrarily large string and crash with an unrecoverable out-of-memory error.",
"affected": [
{
"package": {
"name": "github.com/lib/pq",
"ecosystem": "Go"
},
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "1.11.0"
}
]
}
],
"ecosystem_specific": {
"imports": [
{
"path": "github.com/lib/pq",
"symbols": [
"Connector.Connect",
"DialOpen",
"Driver.Open",
"NewDialListener",
"NewListener",
"NewListenerConn",
"Open",
"conn.Begin",
"conn.BeginTx",
"conn.Commit",
"conn.Exec",
"conn.ExecContext",
"conn.Ping",
"conn.Prepare",
"conn.PrepareContext",
"conn.Query",
"conn.QueryContext",
"conn.Rollback",
"conn.recvMessage",
"rows.Close",
"rows.Next",
"stmt.Close",
"stmt.Exec",
"stmt.ExecContext",
"stmt.Query",
"stmt.QueryContext"
]
}
]
}
}
],
"references": [
{
"type": "REPORT",
"url": "https://github.com/golang/vulndb/issues/6173"
}
],
"database_specific": {
"url": "https://pkg.go.dev/vuln/GO-2026-6173",
"review_status": "REVIEWED"
}
}