CVE-2026-4427 - Github.com/jackc/pgproto3: pgproto3: denial of service via negative field length in datarow message
CVE ID :CVE-2026-4427
Published : March 19, 2026, 2:24 p.m. | 37 minutes ago
Description :A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 19, 2026, 2:24 p.m. | 37 minutes ago
Description :A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.
Severity: 7.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...