p
gx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.
References
Configurations
Configuration 1 (hide)
|
History
04 Dec 2025, 17:33
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Pgx Project
Pgproto3 Project pgproto3 Pgx Project pgx Pgproto3 Project |
|
| CPE | cpe:2.3:a:pgx_project:pgx:*:*:*:*:*:go:*:* cpe:2.3:a:pgproto3_project:pgproto3:*:*:*:*:*:go:*:* |
|
| References | () https://github.com/jackc/pgproto3/commit/945c2126f6db8f3bea7eeebe307c01fe92bca007 - Patch | |
| References | () https://github.com/jackc/pgproto3/security/advisories/GHSA-7jwh-3vrq-q3m8 - Vendor Advisory | |
| References | () https://github.com/jackc/pgx/commit/adbb38f298c76e283ffc7c7a3f571036fea47fd4 - Patch | |
| References | () https://github.com/jackc/pgx/commit/c543134753a0c5d22881c12404025724cb05ffd8 - Patch | |
| References | () https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df - Patch | |
| References | () https://github.com/jackc/pgx/security/advisories/GHSA-mrww-27vc-gghv - Vendor Advisory | |
| References | () https://www.youtube.com/watch?v=Tfg1B8u1yvE - Press/Media Coverage |
12 Dec 2024, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 09:04
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/jackc/pgproto3/commit/945c2126f6db8f3bea7eeebe307c01fe92bca007 - | |
| References | () https://github.com/jackc/pgproto3/security/advisories/GHSA-7jwh-3vrq-q3m8 - | |
| References | () https://github.com/jackc/pgx/commit/adbb38f298c76e283ffc7c7a3f571036fea47fd4 - | |
| References | () https://github.com/jackc/pgx/commit/c543134753a0c5d22881c12404025724cb05ffd8 - | |
| References | () https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df - | |
| References | () https://github.com/jackc/pgx/security/advisories/GHSA-mrww-27vc-gghv - |
Information
Published : 2024-03-06 19:15
Updated : 2025-12-04 17:33
NVD link : CVE-2024-27304
Mitre link : CVE-2024-27304
CVE.ORG link : CVE-2024-27304
JSON object : View
Products Affected