CVE-2026-33816 is a critical memory-safety vulnerability affecting the PostgreSQL driver library github.com/pgx/v5. This flaw has a CVSS score of 9.8, indicating severe potential impact across confidentiality, integrity, and availability. The vulnerability can be exploited remotely over the network without authentication or user interaction, making it highly accessible to threat actors. Based on current indicators, there is no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and shows minimal community engagement on the Hot List. However, organizations should prioritize patching efforts given the critical severity rating and the ease of exploitation, regardless of current exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.9.0CPE matchmatch criteria | cpe:2.3:a:jackc:pgx:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.