CVE-2026-32286Disclosure(jackc / pgproto3)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-129CWE-1285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pgproto3

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
pgproto3

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-26: 1Technical Details · 2026-03-26: 103-26
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CVE@CVEnew
    Disclosure

    CVE-2026-32286 The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field le… https://www.cve.org/CVERecord?id=CVE-2026-32286

    Post summary

    The text reports a vulnerability in PostgreSQL’s DataRow.Decode function where a malicious server can send a DataRow message with a negative field length, indicating improper input validation.

    00000121
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjackcpgproto3-go-

Explore more