CVE-2026-32286 affects components utilizing the DataRow.Decode function, likely within a Go-based PostgreSQL client library, where it fails to properly validate field lengths. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This flaw leads to a slice bounds out of range panic, resulting in a high impact to availability (Denial of Service) for the affected client or application. The CVSSv3.1 score is 7.5 (High), indicating a network-exploitable vulnerability with low attack complexity and no user interaction required. Currently, there is no evidence of active exploitation, nor is public exploit code available on platforms like Metasploit or ExploitDB, and it is not listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, <= 2.3.3CPE matchmatch criteria | cpe:2.3:a:jackc:pgproto3:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.