The number and severity of CVEs published that impact products developed by Jackc over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33816CRITICAL Memory-safety vulnerability in github.com/jackc/pgx/v5. | Apr 7, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-33815CRITICAL Memory-safety vulnerability in github.com/jackc/pgx/v5. | Apr 7, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-41889CRITICAL pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used | May 8, 2026 | 9.8 | 36 | NO | NO |
CVE-2024-27304CRITICAL pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the ca | Mar 6, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-32286HIGH The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing | Mar 26, 2026 | 7.5 | 29 | NO | NO |
CVE-2024-27289HIGH pgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is use | Mar 6, 2024 | 8.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jackc.
Media articles that mention a CVE ID that affects a product developed by Jackc — matched by CVE ID, not by vendor name.