CVE-2026-33816
HashiCorp Vault vulnerability analysis and mitigation

Overview

CVE-2026-33816 is a memory-safety vulnerability in the github.com/jackc/pgx/v5 Go PostgreSQL driver that enables memory corruption via malicious database responses. It affects all versions of github.com/jackc/pgx/v5 prior to 5.9.0. The vulnerability was published on April 7, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory). Downstream products including IBM Security Verify Access OIDC Provider and IBM Verify Antenna are also affected (IBM Advisory, IBM Verify Antenna).

Technical details

The vulnerability is classified under CWE-20 (Improper Input Validation), where the pgx/v5 driver fails to properly validate responses received from a PostgreSQL database server, leading to memory-safety violations (GitHub Advisory). An attacker controlling or able to intercept a database server's responses can craft malicious protocol messages that trigger memory corruption in the client application. The attack requires no authentication, no user interaction, and is network-accessible with low complexity, making it exploitable in scenarios where an attacker can act as a malicious or compromised database server. The Go vulnerability database tracks this issue as GO-2026-4772 (Go Vuln DB).

Impact

Successful exploitation can result in denial of service, information disclosure, or arbitrary code execution within the context of the application using the affected pgx/v5 driver (GitHub Advisory). All three security pillars — confidentiality, integrity, and availability — are rated as high impact. In production environments, this could allow an attacker to compromise application data, disrupt database-dependent services, or potentially pivot to further systems if code execution is achieved (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.022% (6th percentile), indicating a currently low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Nessus (IDs 305254, 315508) and Qualys (ID 6050605), enabling scanner-based identification of affected systems.

Exploitation steps

  1. Identify target applications: Locate Go applications using github.com/jackc/pgx/v5 versions prior to 5.9.0 that connect to a PostgreSQL database, using dependency scanning tools or reviewing go.mod files.
  2. Position as malicious database server: Establish a man-in-the-middle position between the vulnerable application and its database, or set up a rogue PostgreSQL server that the target application connects to (e.g., via DNS poisoning, misconfigured connection strings, or supply chain compromise).
  3. Craft malicious database responses: Send specially crafted PostgreSQL protocol messages that exploit the improper input validation flaw in the pgx/v5 driver, triggering memory corruption in the client application.
  4. Achieve impact: Depending on the nature of the memory corruption, cause a denial of service (application crash), leak sensitive in-memory data (information disclosure), or achieve code execution within the application process (GitHub Advisory, Go Vuln DB).

Indicators of compromise

  • Network: Unexpected or unauthorized PostgreSQL server connections from application hosts; connections to unfamiliar database endpoints or IP addresses not matching known database infrastructure.
  • Logs: Application crash logs or Go runtime panic traces referencing pgx/v5 components; unexpected database connection errors or protocol parsing failures in application logs.
  • Process: Abnormal termination of Go application processes with memory-related errors (e.g., segmentation faults, out-of-bounds access panics); unexpected child processes spawned from database-connected application processes.
  • File System: Core dump files generated by Go application crashes in the working directory of database-connected services.

Mitigation and workarounds

The primary remediation is to upgrade github.com/jackc/pgx/v5 to version 5.9.0 or later, which contains the fix (GitHub Advisory). As a compensating control, implement network segmentation to restrict database connections to trusted, known-good database servers only, reducing the risk of a malicious server triggering the vulnerability. IBM has released patches for affected products: IBM Security Verify Access OIDC Provider and IBM Verify Antenna — users should apply the relevant IBM security bulletins (IBM Advisory, IBM Verify Antenna). Red Hat has also issued errata (RHSA-2026:19137, RHSA-2026:17789, RHSA-2026:24479, RHSA-2026:24475) for affected packages in their ecosystem.

Community reactions

IBM issued security bulletins for two affected products — IBM Security Verify Access OIDC Provider and IBM Verify Antenna — acknowledging the vulnerability and providing remediation guidance (IBM Advisory, IBM Verify Antenna). Red Hat issued multiple errata addressing the vulnerability in their product lines. The CloudNativePG project also released versions 1.29.1 and 1.28.3 with a critical CVE fix referencing this issue (PostgreSQL News). No significant independent researcher commentary or social media discussion has been identified.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

golang-github-jackc-pgx-v5: 5.9.2-1

Fixed

Ubuntu

Unknown

devel

golang-github-jackc-pgx-v5

Unknown

resolute

golang-github-jackc-pgx-v5

Unknown

resolute (esm-apps)

golang-github-jackc-pgx-v5

Unknown

RHEL / CentOS

Fixed

OpenShift

el9:odf4/cephcsi-rhel9-0:v4.20.15

Fixed

RHEL 10

go-fdo-server-0:1.0.1-1.el10_2.src

Fixed

SourceThis report was generated using AI

Related HashiCorp Vault vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84304HIGH8.7
  • cAdvisor logocAdvisor
  • envoy-gateway-fips-1.8
NoYesSep 01, 2026
CVE-2026-56854HIGH7.5
  • New Relic Agent logoNew Relic Agent
  • filebrowser-fips
NoYesAug 28, 2026
CVE-2026-5006MEDIUM6.8
  • HashiCorp Vault logoHashiCorp Vault
  • cpe:2.3:a:hashicorp:vault
NoYesAug 24, 2026
CVE-2026-84303MEDIUM6.3
  • New Relic Agent logoNew Relic Agent
  • kubescape-fips
NoYesSep 01, 2026
CVE-2026-45404MEDIUM5.9
  • HashiCorp Vault logoHashiCorp Vault
  • flipt-fips-2
NoYesAug 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management