๐Ÿ” CVE Alert

CVE-2026-41889

UNKNOWN 0.0

pgx: SQL Injection via placeholder confusion with dollar quoted string literals

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker. This issue has been patched in version 5.9.2.

CWE CWE-89
Vendor jackc
Product pgx
Published May 8, 2026
Last Updated May 8, 2026
Stay Ahead of the Next One

Get instant alerts for jackc pgx

Be the first to know when new unknown vulnerabilities affecting jackc pgx are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

jackc / pgx
< 5.9.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jackc/pgx/security/advisories/GHSA-j88v-2chj-qfwx github.com: https://github.com/jackc/pgx/commit/60644f84918a8af66d14a4b0d865d4edafd955da github.com: https://github.com/jackc/pgx/releases/tag/v5.9.2