
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33816 is a memory-safety vulnerability in the github.com/jackc/pgx/v5 Go PostgreSQL driver that enables memory corruption via malicious database responses. It affects all versions of github.com/jackc/pgx/v5 prior to 5.9.0. The vulnerability was published on April 7, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory). Downstream products including IBM Security Verify Access OIDC Provider and IBM Verify Antenna are also affected (IBM Advisory, IBM Verify Antenna).
The vulnerability is classified under CWE-20 (Improper Input Validation), where the pgx/v5 driver fails to properly validate responses received from a PostgreSQL database server, leading to memory-safety violations (GitHub Advisory). An attacker controlling or able to intercept a database server's responses can craft malicious protocol messages that trigger memory corruption in the client application. The attack requires no authentication, no user interaction, and is network-accessible with low complexity, making it exploitable in scenarios where an attacker can act as a malicious or compromised database server. The Go vulnerability database tracks this issue as GO-2026-4772 (Go Vuln DB).
Successful exploitation can result in denial of service, information disclosure, or arbitrary code execution within the context of the application using the affected pgx/v5 driver (GitHub Advisory). All three security pillars — confidentiality, integrity, and availability — are rated as high impact. In production environments, this could allow an attacker to compromise application data, disrupt database-dependent services, or potentially pivot to further systems if code execution is achieved (Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.022% (6th percentile), indicating a currently low probability of exploitation within the next 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Nessus (IDs 305254, 315508) and Qualys (ID 6050605), enabling scanner-based identification of affected systems.
github.com/jackc/pgx/v5 versions prior to 5.9.0 that connect to a PostgreSQL database, using dependency scanning tools or reviewing go.mod files.The primary remediation is to upgrade github.com/jackc/pgx/v5 to version 5.9.0 or later, which contains the fix (GitHub Advisory). As a compensating control, implement network segmentation to restrict database connections to trusted, known-good database servers only, reducing the risk of a malicious server triggering the vulnerability. IBM has released patches for affected products: IBM Security Verify Access OIDC Provider and IBM Verify Antenna — users should apply the relevant IBM security bulletins (IBM Advisory, IBM Verify Antenna). Red Hat has also issued errata (RHSA-2026:19137, RHSA-2026:17789, RHSA-2026:24479, RHSA-2026:24475) for affected packages in their ecosystem.
IBM issued security bulletins for two affected products — IBM Security Verify Access OIDC Provider and IBM Verify Antenna — acknowledging the vulnerability and providing remediation guidance (IBM Advisory, IBM Verify Antenna). Red Hat issued multiple errata addressing the vulnerability in their product lines. The CloudNativePG project also released versions 1.29.1 and 1.28.3 with a critical CVE fix referencing this issue (PostgreSQL News). No significant independent researcher commentary or social media discussion has been identified.
Fix availability across major Linux distributions and their releases.
devel
golang-github-jackc-pgx-v5
resolute
golang-github-jackc-pgx-v5
resolute (esm-apps)
golang-github-jackc-pgx-v5
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."