CVE-2026-33815Patch(jackc / pgx)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jackc pgx systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Memory-safety vulnerability in github.com/jackc/pgx/v5.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pgx

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-07); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
pgx

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-10: 2Mentions · 2026-04-11: 1Patch / Workaround · 2026-04-10: 2Patch / Workaround · 2026-04-11: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-11: 104-0704-1004-11
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure2
2026-04-102
Patch2
2026-04-111
Patch1
Full discourse5 posts
  • JFrog Security@JFrogSecurity
    Patch

    PSA regarding CVE-2026-33815 and CVE-2026-33816 (Critical CVEs in jackc/pgx). Note that these issues were fixed in jackc/pgx v5.9.0. Most public sources still erroneously claim the latest version (5.9.1) is vulnerable

    Post summary

    The PSA confirms that CVE-2026-33815 and CVE-2026-33816 have been resolved in jackc/pgx v5.9.0 and corrects misinformation that the newer v5.9.1 remains vulnerable.

    11072905
    5.3K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical memory-safety vulnerability (CVE-2026-33815) affects `pgx`, potentially leading to system instability or code execution. Monitor for patch release. #MemorySafety #CVE #InfoSec https://www.pulsepatch.io/posts/cve-2026-33815-pgx-memory-safety

    Post summary

    The tweet announces a critical memory‑safety flaw in pgx and urges users to watch for a forthcoming patch.

    0000061
    11 followersView on X
  • JFrog Security@JFrogSecurity
    Patch

    Fix commits - CVE-2026-33815 https://github.com/jackc/pgx/commit/6dbad4cafdb8a4daab7ff79c858c95da4b6109e8 CVE-2026-33816 https://github.com/jackc/pgx/commit/025d48ccb90efcebdb8ccc67079adddcde3771d5 Requests for updating Go vulndb - https://github.com/golang/vulndb/issues/4943 https://github.com/golang/vulndb/issues/4944

    Post summary

    Fix commits for CVE-2026-33815 and CVE-2026-33816 are provided, along with requests for updating the Go vulnerability database.

    00000195
    3.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33815 Memory-Safety Vulnerability in http://github.com/jackc/pgx/v5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33815 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The notice logs CVE-2026-33815 as a memory-safety flaw in the pgx/v5 GitHub repo, providing alert subscription links but no patches, PoC, or exploit details.

    0000043
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33815 Memory-safety vulnerability in http://github.com/jackc/pgx/v5. https://www.cve.org/CVERecord?id=CVE-2026-33815

    Post summary

    The statement references CVE‑2026‑33815 in the pgx repository, noting it as a memory‑safety flaw but providing no PoC, exploit, active usage, or patch information.

    00000127
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjackcpgx-go-

Explore more