Known vulnerabilities in PostgreSQL driver and toolkit for Go
Vendor:
Jack Christensen
Software:
PostgreSQL driver and toolkit for Go
Software CPE:
cpe:2.3:a:jackc:pgx:*:*:*:*:*:*:*:*
Website:
https://www.jackchristensen.com/
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.4
Breakdown by Severity Chart
5.10.0
5.9.2
5.9.1
5.9.0
5.8.0
5.7.6
5.7.5
5.7.4
5.7.3
5.7.2
5.7.1
5.7.0
5.6.0
5.5.5
5.5.4
5.5.3
5.5.2
5.5.1
5.5.0
5.4.3
5.4.2
5.4.1
5.4.0
5.3.1
5.3.0
5.2.0
5.1.1
5.1.0
5.0.4
5.0.3
5.0.2
5.0.1
5.0.0
4.18.3
4.18.2
4.18.1
4.18.0
4.17.2
4.17.1
4.17.0
4.16.1
4.16.0
4.15.0
4.14.1
4.14.0
4.13.0
4.12.0
4.11.0
4.10.1
4.10.0
4.9.2
4.9.1
4.9.0
4.8.1
4.8.0
4.7.2
4.7.1
4.7.0
4.6.0
4.5.0
4.4.1
4.4.0
4.3.0
4.2.1
4.2.0
4.1.2
4.1.1
4.1.0
4.0.1
4.0.0
3.6.2
3.6.1
3.6.0
3.5.0
3.4.0
3.3.0
3.2.0
3.1.0
3.0.1
3.0.0
2.11.0
2.10.0
2.9.0
2.8.1
2.8.0
2.7.1
2.7.0
2.6.0
2.5.0
2.4.0
2.3.0
2.2.0
2.1.0
2.0.0
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU126575 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2026-41889 |
CWE-89 | Medium | 5.9.2 | 20.04.2026 |
SB20260420104 |
||
| #VU87833 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-27289 |
CWE-89 | Medium | 4.18.2 | 26.03.2024 |
SB2024032656 SB2024040339 SB2024041529 and 5 more |
||
| #VU87832 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-27304 |
CWE-89 | Medium | 4.18.2, 5.5.4 | 26.03.2024 |
SB2024032656 SB2024032657 SB2024040339 and 5 more |