Vulnerability Report: GO-2026-6172
withdrawn- CVE-2026-56873
- Affects: github.com/lib/pq
- Published: Aug 18, 2026
- Modified: Aug 19, 2026
- Withdrawn: Aug 18, 2026
(This report has been withdrawn with reason: "Report mistakenly added without having CVE / GHSA associated"). github.com/lib/pq allocates the backend-declared PostgreSQL frame payload before applying a protocol length bound or a phase-specific message-type check. A malicious server or active network attacker on an unauthenticated connection can send frame headers declaring multi-gigabyte or invalid-phase payloads, forcing large allocations that lead to memory exhaustion and runtime out-of-memory crashes.
Affected Packages
-
PathGo VersionsSymbols
-
all versions, no known fixed
Aliases
References
Feedback
See anything missing or incorrect?
Suggest an edit to this report.