CVE-2024-27304Patch(jackc / pgproto3)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch jackc pgproto3 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89CWE-190

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pgproto3
  • pgx

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
pgproto3pgx

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-23: 1PoC Mentioned / Linked · 2026-03-23: 1Exploit Tool / Code · 2026-03-23: 1Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 103-23
Signal classification1 categories
Patch
1100.0%
Referenced assets3 URLs
Full discourse1 post
  • dbugs@ptdbugs
    Patch

    pgx SQL Injection via Protocol Message Size Overflow CVE: CVE-2024-27304 PT-Identifier: PT-2024-2043 Vendor: jackc Product: pgx (PostgreSQL Driver) CVSS: 9.8 Credits: n/a Description: pgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large message to be sent as multiple messages under the attacker's control. The problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user input large enough to cause a single query or bind message to exceed 4 GB in size. References: https://dbugs.ptsecurity.com/vulnerability/CVE-2024-27304 Exploits: https://github.com/flying-owl/Go-PGX-Vulnerability-POC-Public-Mirror https://github.com/roaris/CVE-2024-27304-PoC #dbugs_vuln

    Post summary

    The entry details a high‑severity SQL injection vulnerability (CVE‑2024‑27304), provides PoC code, but primarily highlights the vendor’s patch releases and a recommended input‑size workaround.

    0001191
    733 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appjackcpgproto3-go-
Appjackcpgx-go-

Explore more