Junglewise Threat Intelligence

CVE-2026-33816: jackc pgx memory safety vulnerability in pgproto3

CVE-2026-33816 · Severity: critical · CVSS 9.8 · Published 2026-04-07

Technologies: Jack Christensen Pgx, github.com/jackc/pgx/v5 (Go). Vendors: Jack Christensen, Go.

Executive brief

A critical memory-safety vulnerability exists in pgx, a popular Go library used to connect applications to PostgreSQL databases. An attacker could potentially exploit this flaw to cause application crashes, execute unauthorized code, or access sensitive data. Organizations using this library should update to version 5.9.0 or later to ensure the security and stability of their database connections.

Technical details

A memory-safety vulnerability exists in the pgproto3 component of the jackc/pgx/v5 library. The flaw is located within the Backend.Receive and FunctionCall.Decode functions, which are responsible for parsing PostgreSQL wire protocol messages. A remote, unauthenticated attacker can exploit this by sending specially crafted network packets to an application using the library, potentially leading to arbitrary code execution or a denial-of-service (DoS) condition. The issue is addressed in version 5.9.0.

Affected products

  • jackc pgx/v5 < 5.9.0

Timeline

  • 2026-04-07: disclosed
  • 2026-04-07: advisory
  • 2026-05-21: other: NIST analysis modified

References

Related threats