Executive brief
The AWS Advanced Go Wrapper is a library used to connect applications to Amazon Aurora PostgreSQL databases. A security vulnerability has been identified that allows a user with low-level database access to trick other users, including administrators, into running malicious code. This could lead to a full takeover of the database instance, unauthorized data access, or service disruption.
Technical details
An untrusted search path vulnerability (CWE-426) exists in the GlobalDatabasePlugin of the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL. A remote authenticated attacker with low privileges can exploit this by creating a specially crafted database function. When a higher-privileged user (such as an rds_superuser) connects to the cluster through the affected wrapper, the malicious function may be executed with that user's permissions. This allows the attacker to escalate privileges and gain full control over the RDS instance. The issue is resolved in the 2026-05-26 release (v1.1.1 and related sub-module updates).
Affected products
- AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL <= 1.1.0 (or release 2026-04-06)
Timeline
- 2026-05-20: disclosed: Initial GitHub advisory publication
- 2026-05-26: patched: Release 2026-05-26 published
- 2026-06-05: advisory: AWS Security Bulletin and NVD publication
- 2026-06-11: other: GitHub Advisory updated and reviewed
References
- https://github.com/aws/aws-advanced-go-wrapper/security/advisories/GHSA-r236-5pc3-3qcp
- https://aws.amazon.com/security/security-bulletins/2026-039-aws
- https://github.com/aws/aws-advanced-go-wrapper/releases/tag/release-2026-05-26
- https://api.github.com/repos/aws/aws-advanced-go-wrapper/security-advisories/GHSA-r236-5pc3-3qcp