{"id":"CVE-2026-33815","aliases":["GO-2026-4771"],"url":"https://o3.security/vulnerability/CVE-2026-33815","summary":"pgx contains memory-safety vulnerability","details":"[pgx](github.com/jackc/pgx/v5) is a pure Go driver and toolkit for PostgreSQL. pgx prior to v5.9.0 contains a memory-safety vulnerability.","published":"2026-04-07T18:31:36Z","modified":"2026-09-10T03:50:44.892822027Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.00605,"percentile":0.47444,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/jackc/pgx/v5","fixedVersion":"5.9.0"}],"fix":{"url":"https://github.com/jackc/pgx/commit/6dbad4cafdb8a4daab7ff79c858c95da4b6109e8","label":"jackc/pgx@6dbad4c"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33815"},{"type":"WEB","url":"https://github.com/jackc/pgx/issues/2519"},{"type":"WEB","url":"https://github.com/jackc/pgx/issues/2530"},{"type":"WEB","url":"https://github.com/jackc/pgx/commit/6dbad4cafdb8a4daab7ff79c858c95da4b6109e8"},{"type":"WEB","url":"https://pkg.go.dev/vuln/GO-2026-4771"},{"type":"PACKAGE","url":"github.com/jackc/pgx/v5"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:44.892822027Z"}}