PatchSiren

github.com/jackc/pgx/v5 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL github.com/jackc/pgx/v5 CVE published 2026-04-07

CVE-2026-33816

CVE-2026-33816 is a critical memory-safety vulnerability in github.com/jackc/pgx/v5. NVD rates it 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating a remotely reachable issue with severe confidentiality, integrity, and availability impact. The NVD record and the linked Go advisory point to affected pgx/v5 versions before 5.9.0.

CRITICAL github.com/jackc/pgx/v5 CVE published 2026-04-07

CVE-2026-33815

CVE-2026-33815 is a critical memory-safety vulnerability in github.com/jackc/pgx/v5. The official NVD record rates it CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), which means it can have severe impact if exposed in production. The supplied official sources also point to the Go vulnerability advisory GO-2026-4771 for remediation guidance. No additional root-cause detail or fixed-version information [truncated]