FlawAtlas
Search the atlas
CVE-2026-4427 High

Duplicate Advisory: pgproto3: Negative field length panics in DataRow.Decode

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-jqcq-xjh3-6g23. This link is maintained to preserve external references. ## Original Description A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.

Exploit probability Not scored
Published March 19, 2026
Required by Not available
Last source change March 30, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go github.com/jackc/pgproto3/v2

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-x6gf-mpr2-68h6

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-jqcq-xjh3-6g23. This link is maintained to preserve external references. ## Original Description A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.

View original source

05 / REFERENCES

Further evidence