CVE-2026-4427 Details
Description
Rejected reason: Duplicate of CVE-2026-32286
A denial-of-service vulnerability has been identified in the Jackc Pgproto3 library, specifically in version 2.3.3. This vulnerability arises from improper validation of field lengths in the DataRow message of the PostgreSQL wire protocol. A malicious or compromised PostgreSQL server can exploit this flaw by sending a DataRow message with a negative field length, causing a slice bounds out-of-range panic. As a result, any Go application using this library to connect to a PostgreSQL server can be crashed, terminating the process without recovery.
Users are advised to update to Jackc Pgproto3 version 2.3.4 or later, where this vulnerability has been fixed. Monitor the Jackc Pgproto3 repository for the release of the patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Mar 30, 2026 | CVE Rejected | [email protected] |
| Mar 30, 2026 | CVE Modified | [email protected] |
| Mar 19, 2026 | New CVE Received | [email protected] |