go package report

Is github.com/jackc/pgx/v4 safe?

2 known vulnerabilities, worst severity HIGH.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


      cvss
      0.0
      high

      severity out of 10

      epss
      0.00%
      medium

      chance of exploitation in 30 days, 56th percentile of all CVEs

      xyz score
      0.0
      low

      CyberXYZ composite out of 10

      fig. 01 — GHSA-m7wr-2xf7-cm9p, the advisory selected below

      // 2 advisories

      GHSA-m7wr-2xf7-cm9p

      HIGHCVE-2024-27289
      // impact

      SQL injection can occur when all of the following conditions are met:

      • The non-default simple protocol is used.
      • A placeholder for a numeric value must be immediately preceded by a minus.
      • There must be a second placeholder for a string value after the first placeholder; both

      must be on the same line.

      • Both parameter values must be user-controlled.

      e.g.

      Simple mode must be enabled:

      // connection string includes "prefer_simple_protocol=true"
      // or
      // directly enabled in code
      config.ConnConfig.PreferSimpleProtocol = true

      Parameterized query:

      SELECT * FROM example WHERE result=-$1 OR name=$2;

      Parameter values:

      $1 => -42 $2 => "foo\n 1 AND 1=0 UNION SELECT FROM secrets; --"

      Resulting query after preparation:

      SELECT * FROM example WHERE result=--42 OR name= 'foo
      1 AND 1=0 UNION SELECT * FROM secrets; --';
      // patches

      The problem is resolved in v4.18.2.

      // workarounds

      Do not use the simple protocol or do not place a minus directly before a placeholder.

      // cvss v3.1 vector

      CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

      Attack vector
      Network
      Attack complexity
      High
      Privileges required
      None
      User interaction
      None
      Scope
      Unchanged
      Confidentiality
      High
      Integrity
      High
      Availability
      High

      Checked 2026-09-28 at 19:46 UTC. The most recent advisory here was published 2024-03-04. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.