
Go'nun pgx kütüphanesinde dollar-quoted string ile placeholder karışıyor, SQL injection doğuyor. "Go yazdım, memory safe" diyenler SQL injection'dan da korunduğunu sanıyordu herhalde. Dil güvenli olabilir, developer değil. CVE-2026-41889
Post summary
The post discloses that a flaw in Go's pgx library (CVE-2026-41889) allows dollar‑quoted strings to corrupt parameter placeholders, resulting in SQL injection. No evidence of active exploitation, PoC, or patch is provided.

