CVE-2026-33815 is a critical memory-safety vulnerability affecting github.com/jackc/pgx/v5, a widely-used PostgreSQL driver library. The vulnerability carries a CVSS score of 9.8, indicating severe risk with high potential for compromise. The attack vector is network-based with low complexity, requiring no privileges or user interaction, making it relatively straightforward to exploit remotely. The vulnerability poses significant threats across all three security dimensions: confidentiality, integrity, and availability. An attacker exploiting this flaw could potentially execute arbitrary code, exfiltrate sensitive data, or disrupt system availability. At present, there is no evidence of active exploitation in the wild, as the vulnerability does not appear on the KEV catalog and has inactive status on threat tracking lists. The EPSS score of 0.000560 suggests current real-world exploitation probability is low, though the community attention and risk score of 55.0 indicate this remains a serious concern requiring prompt patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:jackc:pgx:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.