pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.
References
Configurations
Configuration 1 (hide)
|
History
04 Dec 2025, 17:33
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:pgproto3_project:pgproto3:*:*:*:*:*:go:*:* cpe:2.3:a:pgx_project:pgx:*:*:*:*:*:go:*:* |
|
| References | () https://github.com/jackc/pgproto3/commit/945c2126f6db8f3bea7eeebe307c01fe92bca007 - Patch | |
| References | () https://github.com/jackc/pgproto3/security/advisories/GHSA-7jwh-3vrq-q3m8 - Vendor Advisory | |
| References | () https://github.com/jackc/pgx/commit/adbb38f298c76e283ffc7c7a3f571036fea47fd4 - Patch | |
| References | () https://github.com/jackc/pgx/commit/c543134753a0c5d22881c12404025724cb05ffd8 - Patch | |
| References | () https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df - Patch | |
| References | () https://github.com/jackc/pgx/security/advisories/GHSA-mrww-27vc-gghv - Vendor Advisory | |
| References | () https://www.youtube.com/watch?v=Tfg1B8u1yvE - Press/Media Coverage | |
| First Time |
Pgx Project pgx
Pgproto3 Project pgproto3 Pgproto3 Project Pgx Project |
12 Dec 2024, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 09:04
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/jackc/pgproto3/commit/945c2126f6db8f3bea7eeebe307c01fe92bca007 - | |
| References | () https://github.com/jackc/pgproto3/security/advisories/GHSA-7jwh-3vrq-q3m8 - | |
| References | () https://github.com/jackc/pgx/commit/adbb38f298c76e283ffc7c7a3f571036fea47fd4 - | |
| References | () https://github.com/jackc/pgx/commit/c543134753a0c5d22881c12404025724cb05ffd8 - | |
| References | () https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df - | |
| References | () https://github.com/jackc/pgx/security/advisories/GHSA-mrww-27vc-gghv - |
06 Mar 2024, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-03-06 19:15
Updated : 2025-12-04 17:33
NVD link : CVE-2024-27304
Mitre link : CVE-2024-27304
CVE.ORG link : CVE-2024-27304
JSON object : View
Products Affected
pgproto3_project
- pgproto3
pgx_project
- pgx
