Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33815

39
FAUCET Score

CVE-2026-33815 is a critical memory-safety vulnerability affecting github.com/jackc/pgx/v5, a widely-used PostgreSQL driver library. The vulnerability carries a CVSS score of 9.8, indicating severe risk with high potential for compromise. The attack vector is network-based with low complexity, requiring no privileges or user interaction, making it relatively straightforward to exploit remotely. The vulnerability poses significant threats across all three security dimensions: confidentiality, integrity, and availability. An attacker exploiting this flaw could potentially execute arbitrary code, exfiltrate sensitive data, or disrupt system availability. At present, there is no evidence of active exploitation in the wild, as the vulnerability does not appear on the KEV catalog and has inactive status on threat tracking lists. The EPSS score of 0.000560 suggests current real-world exploitation probability is low, though the community attention and risk score of 55.0 indicate this remains a serious concern requiring prompt patching.

Impacted Technologies

VendorProductVersion(s)CPE
All Versions ImpactedCPE matchmatch criteria
cpe:2.3:a:jackc:pgx:*:*:*:*:*:go:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.60%
Probability of exploitation in next 30 days
EPSS Percentile
45.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0060 is in the 26th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/jackc/pgx/v5Fixed in: 5.9.0

Vendor Advisories (1)

goGHSA-xgrm-4fwx-7qm8critical

pgx contains memory-safety vulnerability

Apr 7, 2026

References

access.redhat.com / errata/RHSA-2026:11070
access.redhat.com / errata/RHSA-2026:11217
access.redhat.com / errata/RHSA-2026:13791
access.redhat.com / errata/RHSA-2026:13829
access.redhat.com / errata/RHSA-2026:17789
access.redhat.com / errata/RHSA-2026:22423
access.redhat.com / errata/RHSA-2026:24475
access.redhat.com / errata/RHSA-2026:24479
access.redhat.com / errata/RHSA-2026:24482
access.redhat.com / errata/RHSA-2026:24503
access.redhat.com / errata/RHSA-2026:24539
access.redhat.com / errata/RHSA-2026:25273
access.redhat.com / errata/RHSA-2026:26636
access.redhat.com / errata/RHSA-2026:36796
access.redhat.com / errata/RHSA-2026:40984
access.redhat.com / errata/RHSA-2026:41019
access.redhat.com / security/cve/CVE-2026-33815
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-33815.json
pkg.go.dev / vuln/GO-2026-4771
Third Party Advisory