Description

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

INFO

Published Date :

2026-03-26T19:40:51.974Z

Last Modified :

2026-03-26T19:40:51.974Z

Source :

Go
AFFECTED PRODUCTS

The following products are affected by CVE-2026-32286 vulnerability.

Vendors Products
Jackc
  • Pgproto3

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact