{"id":"GHSA-7wq2-32h4-9hc9","aliases":["GO-2025-4119"],"url":"https://o3.security/vulnerability/GHSA-7wq2-32h4-9hc9","summary":"AWS Advanced Go Wrapper: Privilege Escalation in Aurora PostgreSQL Instance","details":"### Description of Vulnerability: \nAn issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.\n\nWe recommend customers upgrade to the following versions:  AWS Go Wrapper to 2025-10-17\n\n\n### Source of Vulnerability Report: \nAllistair Ishmael Hakim [allistair.hakim@gmail.com](mailto:allistair.hakim@gmail.com)\n\n\n### Affected products & versions: \nAWS Go Wrapper < 2025-10-17\n\n\n### Platforms:\n MacOS/Windows/Linux","published":"2025-11-13T22:22:34Z","modified":"2026-05-06T23:35:18.227635Z","cvss":{"score":8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/aws/aws-advanced-go-wrapper/awssql","fixedVersion":"1.1.1"},{"ecosystem":"Go","name":"github.com/aws/aws-advanced-go-wrapper/auth-helpers","fixedVersion":"1.0.2"},{"ecosystem":"Go","name":"github.com/aws/aws-advanced-go-wrapper/aws-secrets-manager","fixedVersion":"1.0.2"},{"ecosystem":"Go","name":"github.com/aws/aws-advanced-go-wrapper/federated-auth","fixedVersion":"1.0.2"},{"ecosystem":"Go","name":"github.com/aws/aws-advanced-go-wrapper/iam","fixedVersion":"1.0.2"},{"ecosystem":"Go","name":"github.com/aws/aws-advanced-go-wrapper/mysql-driver","fixedVersion":"1.0.2"},{"ecosystem":"Go","name":"github.com/aws/aws-advanced-go-wrapper/okta","fixedVersion":"1.0.2"},{"ecosystem":"Go","name":"github.com/aws/aws-advanced-go-wrapper/otlp","fixedVersion":"1.0.2"},{"ecosystem":"Go","name":"github.com/aws/aws-advanced-go-wrapper/pgx-driver","fixedVersion":"1.0.2"},{"ecosystem":"Go","name":"github.com/aws/aws-advanced-go-wrapper/xray","fixedVersion":"1.0.2"}],"fix":{"url":"https://github.com/aws/aws-advanced-go-wrapper/pull/270","label":"aws/aws-advanced-go-wrapper#270"},"references":[{"type":"WEB","url":"https://github.com/aws/aws-advanced-go-wrapper/security/advisories/GHSA-7wq2-32h4-9hc9"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-go-wrapper/pull/270"},{"type":"WEB","url":"https://github.com/aws/aws-advanced-go-wrapper/commit/7b405f95fe71db644cd8336ba5fa28b41e89d03e"},{"type":"PACKAGE","url":"https://github.com/aws/aws-advanced-go-wrapper"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-06T23:35:18.227635Z"}}