CVE-2026-33816Disclosure(jackc / pgx)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch jackc pgx systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Memory-safety vulnerability in github.com/jackc/pgx/v5.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pgx

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-07); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
pgx

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-10: 2Mentions · 2026-04-16: 1Mentions · 2026-04-17: 1Patch / Workaround · 2026-04-10: 2Patch / Workaround · 2026-04-17: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-10: 1Technical Details · 2026-04-17: 104-0704-1004-1604-17
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
General
116.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure2
2026-04-102
Patch2
2026-04-161
General1
2026-04-171
Disclosure1
Full discourse6 posts
  • JFrog Security@JFrogSecurity
    Patch

    PSA regarding CVE-2026-33815 and CVE-2026-33816 (Critical CVEs in jackc/pgx). Note that these issues were fixed in jackc/pgx v5.9.0. Most public sources still erroneously claim the latest version (5.9.1) is vulnerable

    Post summary

    The PSA confirms that CVE-2026-33815 and CVE-2026-33816 were fixed in jackc/pgx v5.9.0 and that claims of their presence in v5.9.1 are incorrect.

    11072905
    5.3K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A memory-safety vulnerability (CVE-2026-33816) affects 'jackc/pgx/v5'. Review Go applications using this PostgreSQL driver for potential impact. Patching is advised once available. #GoLang #PostgreSQL #InfoSec https://www.pulsepatch.io/posts/cve-2026-33816-pgx-memory-safety

    Post summary

    The post announces a newly discovered memory‑safety vulnerability in the Go PostgreSQL driver, warns developers to review their applications, and recommends applying a patch once released.

    0000090
    12 followersView on X
  • Binary@nitrocode
    General

    CVE-2026-33816 Interesting

    Post summary

    The excerpt only cites CVE‑2026‑33816 and labels it "Interesting", offering no further technical or actionable details.

    0000048
    1.4K followersView on X
  • JFrog Security@JFrogSecurity
    Patch

    Fix commits - CVE-2026-33815 https://github.com/jackc/pgx/commit/6dbad4cafdb8a4daab7ff79c858c95da4b6109e8 CVE-2026-33816 https://github.com/jackc/pgx/commit/025d48ccb90efcebdb8ccc67079adddcde3771d5 Requests for updating Go vulndb - https://github.com/golang/vulndb/issues/4943 https://github.com/golang/vulndb/issues/4944

    Post summary

    The post lists GitHub commit URLs that fix CVE‑2026‑33815 and CVE‑2026‑33816 and references issue threads for updating the Go vulnerability database, indicating that patches are available but no exploit or PoC is mentioned.

    00000195
    3.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33816 Memory-Safety Vulnerability in http://GitHub.com/jackc/pgx/v5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33816 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces the CVE-2026-33816 memory‑safety vulnerability in gitHub.com/jackc/pgx/v5 and links to a Vulmon report, but offers no PoC, exploit code, or patch details.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33816 Memory-safety vulnerability in http://github.com/jackc/pgx/v5. https://www.cve.org/CVERecord?id=CVE-2026-33816

    Post summary

    The post announces a new CVE (Memory-safety vulnerability) without referencing any PoC, exploit code, active attacks, patches, or debunking claims.

    00000273
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjackcpgx-go-

Explore more