CVE-2026-33815
HashiCorp Vault vulnerability analysis and mitigation

Overview

CVE-2026-33815 is a memory-safety vulnerability in github.com/jackc/pgx/v5, a pure Go driver and toolkit for PostgreSQL. It affects the pgproto3 sub-package in all versions prior to v5.9.0. The vulnerability was published on April 7, 2026, and patched the same day with the release of pgx v5.9.0. It carries a CVSS v3.1 base score of 9.8 (Critical), reflecting network-exploitable, unauthenticated attack potential with high impact across confidentiality, integrity, and availability (Github Advisory). Downstream products including IBM Verify Identity Access OIDC Provider and IBM Verify Antenna are also confirmed affected (IBM Advisory, IBM Verify Antenna).

Technical details

The vulnerability is classified as a memory-safety issue within the pgproto3 package of the pgx Go PostgreSQL driver (no specific CWE has been assigned). Memory-safety vulnerabilities in this context typically arise from improper handling of buffer boundaries or unsafe memory operations when parsing PostgreSQL wire protocol messages, which could allow an attacker to trigger memory corruption. The attack vector is network-based, requires no authentication or user interaction, and has low attack complexity, making it exploitable by any remote party capable of sending crafted PostgreSQL protocol messages to an application using the affected library. References to the upstream fix are available via the pgx GitHub repository commits and issues (Github Advisory, Go Vuln DB).

Impact

Successful exploitation could result in complete compromise of confidentiality, integrity, and availability of systems running applications built with the affected pgx library. An unauthenticated remote attacker could potentially achieve arbitrary code execution, cause application crashes (denial of service), or corrupt data processed by the PostgreSQL driver. Given the library's widespread use in Go-based backend services, the blast radius could extend to any application that uses pgx v5 for database connectivity, including downstream IBM products (Github Advisory, IBM Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.018–0.022%, placing it in the 6th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Despite the absence of active exploitation, the critical CVSS score and zero-authentication requirement make it a high-priority patching target.

Mitigation and workarounds

The primary remediation is to upgrade the github.com/jackc/pgx/v5 Go module to version 5.9.0 or later, which was released on April 7, 2026 (Github Advisory). Organizations using IBM Verify Identity Access OIDC Provider or IBM Verify Antenna should apply the vendor-supplied patches referenced in IBM's security bulletins (IBM Advisory, IBM Verify Antenna). Red Hat has also issued errata (RHSA-2026:17789, RHSA-2026:24479, RHSA-2026:24475) for affected products. As a temporary measure where patching is not immediately possible, restrict network access to services using the affected library to trusted sources only.

Community reactions

IBM issued security bulletins for two affected products — IBM Verify Identity Access OIDC Provider and IBM Verify Antenna — acknowledging the vulnerability and providing remediation guidance (IBM Advisory, IBM Verify Antenna). Red Hat published multiple security advisories (RHSA-2026:17789, RHSA-2026:24479, RHSA-2026:24475) addressing the issue in their product portfolio. The vulnerability was credited to researcher mitar in the GitHub Advisory Database (Github Advisory). No significant social media discussion or broader community controversy has been observed.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

golang-github-jackc-pgx-v5: 5.9.2-1

Fixed

Ubuntu

Unknown

devel

golang-github-jackc-pgx-v5

Unknown

resolute

golang-github-jackc-pgx-v5

Unknown

resolute (esm-apps)

golang-github-jackc-pgx-v5

Unknown

RHEL / CentOS

Fixed

OpenShift

el9:odf4/cephcsi-rhel9-0:v4.20.15

Fixed

RHEL 10

Not Affected

SourceThis report was generated using AI

Related HashiCorp Vault vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84304HIGH8.7
  • cAdvisor logocAdvisor
  • envoy-gateway-fips-1.8
NoYesSep 01, 2026
CVE-2026-56854HIGH7.5
  • New Relic Agent logoNew Relic Agent
  • filebrowser-fips
NoYesAug 28, 2026
CVE-2026-5006MEDIUM6.8
  • HashiCorp Vault logoHashiCorp Vault
  • cpe:2.3:a:hashicorp:vault
NoYesAug 24, 2026
CVE-2026-84303MEDIUM6.3
  • New Relic Agent logoNew Relic Agent
  • kubescape-fips
NoYesSep 01, 2026
CVE-2026-45404MEDIUM5.9
  • HashiCorp Vault logoHashiCorp Vault
  • flipt-fips-2
NoYesAug 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management