CVE-2026-41889
published 2026-05-08CVE-2026-41889: pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted…
low2.3CVSS 4.0
AVNACHATPPRLUINVCNVILVANSCNSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker. This issue has been patched in version 5.9.2.
Affected
130 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| 3scale-amp2 | 3scale-operator-bundle | — | — |
| 3scale-amp2 | 3scale-rhel7-operator | — | — |
| 3scale-amp2 | 3scale-rhel9-operator | — | — |
| advanced-cluster-security | rhacs-main-rhel8 | — | — |
| advanced-cluster-security | rhacs-rhel8-operator | — | — |
| advanced-cluster-security | rhacs-roxctl-rhel8 | — | — |
| advanced-cluster-security | rhacs-scanner-v4-rhel8 | — | — |
| caddyserver | caddy | — | — |
| cryostat | cryostat-storage-rhel9 | — | — |
| custom-metrics-autoscaler | custom-metrics-autoscaler-adapter-rhel9 | — | — |
| custom-metrics-autoscaler | custom-metrics-autoscaler-admission-webhooks-rhel9 | — | — |
| custom-metrics-autoscaler | custom-metrics-autoscaler-rhel9 | — | — |
| custom-metrics-autoscaler | custom-metrics-autoscaler-rhel9-operator | — | — |
| jackc | pgx | < 5.9.2 | 5.9.2 |
| multicluster-engine | assisted-installer-agent-rhel8 | — | — |
| multicluster-engine | assisted-installer-agent-rhel9 | — | — |
| multicluster-engine | assisted-installer-controller-rhel8 | — | — |
| multicluster-engine | assisted-installer-controller-rhel9 | — | — |
| multicluster-engine | assisted-installer-rhel8 | — | — |
| multicluster-engine | assisted-installer-rhel9 | — | — |
| multicluster-engine | assisted-service-8-rhel8 | — | — |
| multicluster-engine | assisted-service-9-rhel9 | — | — |
| multicluster-engine | azure-service-operator-rhel9 | — | — |
| multicluster-engine | cluster-api-provider-aws-rhel9 | — | — |
| multicluster-globalhub | multicluster-globalhub-agent-rhel8 | — | — |