{"id":"GHSA-rgqc-3x5p-6gwg","aliases":["RUSTSEC-2026-0180"],"url":"https://o3.security/vulnerability/GHSA-rgqc-3x5p-6gwg","summary":"postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service","details":"A malicious or compromised server can return a binary `hstore` value with an\ninvalid internal length field, causing the client to panic while decoding it.\n\nApplications that connect only to a trusted database are not exposed; the risk\napplies to clients that may connect to untrusted or user-supplied servers, or\nwhose connection can be intercepted by a man-in-the-middle.","published":"2026-08-24T19:47:49Z","modified":"2026-08-25T02:55:59.424379516Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"postgres-protocol","fixedVersion":"0.6.12"}],"fix":{"url":"https://github.com/rust-postgres/rust-postgres/commit/a7cf84b5c46431cbca9d8ff50508c23f446efa7d","label":"rust-postgres/rust-postgres@a7cf84b"},"references":[{"type":"WEB","url":"https://github.com/rust-postgres/rust-postgres/commit/a7cf84b5c46431cbca9d8ff50508c23f446efa7d"},{"type":"PACKAGE","url":"https://github.com/rust-postgres/rust-postgres"},{"type":"WEB","url":"https://github.com/rust-postgres/rust-postgres/releases/tag/postgres-protocol-v0.6.12"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0180.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-25T02:55:59.424379516Z"}}