| { |
| "schema_version": "1.3.1", |
| "id": "GO-2026-6173", |
| "modified": "0001-01-01T00:00:00Z", |
| "published": "0001-01-01T00:00:00Z", |
| "withdrawn": "2026-08-18T20:23:02Z", |
| "aliases": [ |
| "CVE-2026-56874" |
| ], |
| "summary": "WITHDRAWN: Pre-protocol error reader permits unbounded memory consumption in github.com/lib/pq", |
| "details": "(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). The special-case parser for PostgreSQL pre-protocol plain-text errors in github.com/lib/pq calls bufio.Reader.ReadString(0) without a byte limit. A malicious PostgreSQL endpoint or active network attacker on an unauthenticated transport can send an error message response with non-NUL bytes continuously, causing the client to buffer an arbitrarily large string and crash with an unrecoverable out-of-memory error.", |
| "affected": [ |
| { |
| "package": { |
| "name": "github.com/lib/pq", |
| "ecosystem": "Go" |
| }, |
| "ranges": [ |
| { |
| "type": "SEMVER", |
| "events": [ |
| { |
| "introduced": "1.11.0" |
| } |
| ] |
| } |
| ], |
| "ecosystem_specific": { |
| "imports": [ |
| { |
| "path": "github.com/lib/pq", |
| "symbols": [ |
| "Connector.Connect", |
| "DialOpen", |
| "Driver.Open", |
| "NewDialListener", |
| "NewListener", |
| "NewListenerConn", |
| "Open", |
| "conn.Begin", |
| "conn.BeginTx", |
| "conn.Commit", |
| "conn.Exec", |
| "conn.ExecContext", |
| "conn.Ping", |
| "conn.Prepare", |
| "conn.PrepareContext", |
| "conn.Query", |
| "conn.QueryContext", |
| "conn.Rollback", |
| "conn.recvMessage", |
| "rows.Close", |
| "rows.Next", |
| "stmt.Close", |
| "stmt.Exec", |
| "stmt.ExecContext", |
| "stmt.Query", |
| "stmt.QueryContext" |
| ] |
| } |
| ] |
| } |
| } |
| ], |
| "references": [ |
| { |
| "type": "REPORT", |
| "url": "https://github.com/golang/vulndb/issues/6173" |
| } |
| ], |
| "database_specific": { |
| "url": "https://pkg.go.dev/vuln/GO-2026-6173", |
| "review_status": "REVIEWED" |
| } |
| } |