CVE-2026-41889
Vulnerability Summary
Timeline
Description
pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker. This issue has been patched in version 5.9.2.
CVSS Metrics
- v4.0•LOW•Score: 2.3CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- v4.0•LOW•Score: 2.3CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- v3.1•MEDIUM•Score: 5.9CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N
EPSS Trends
Current EPSS score: 0.36%• Percentile: 29%
Techniques & Countermeasures
- CWE-89•Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
Affected Systems
- chainguard•amass
< 5.1.1-r1
- chainguard•argo-workflow-controller-3.6
all
- chainguard•argo-workflow-controller-3.7
< 3.7.14-r0
- chainguard•argo-workflow-controller-4.0
< 4.0.5-r0
- chainguard•argo-workflow-controller-fips-3.6
all
- chainguard•argo-workflow-controller-fips-3.7
< 3.7.14-r0
- chainguard•argo-workflow-executor-3.6
all
- chainguard•argo-workflow-executor-3.7
< 3.7.14-r0
- chainguard•argo-workflow-executor-4.0
< 4.0.5-r0
- chainguard•argo-workflow-executor-fips-3.6
all
- chainguard•argo-workflows-3.6
all
- chainguard•argo-workflows-3.7
< 3.7.14-r0
- chainguard•argo-workflows-4.0
< 4.0.5-r0
- chainguard•argo-workflows-fips-3.6
all
- chainguard•argo-workflows-fips-3.7
< 3.7.14-r0
- chainguard•authentik-2025.12-go-server
< 2025.12.4-r6
- chainguard•authentik-2026.2-go-server
< 2026.2.1-r6
- chainguard•authentik-fips-2025.12-go-server
< 2025.12.4-r5
- chainguard•authentik-fips-2026.2-go-server
< 2026.2.1-r5
- chainguard•azure-service-operator
< 2.18.0-r7
- chainguard•azure-service-operator-fips
< 2.18.0-r6
- chainguard•bento
< 1.17.0-r2
- chainguard•bento-fips
< 1.17.0-r2
- chainguard•caddy
< 2.11.2-r13
- chainguard•caddy-fips
< 2.11.2-r9
- chainguard•cerbos
< 0.51.0-r19
- chainguard•certificate-transparency-fips-trillian-ctserver
< 1.3.3-r7
- chainguard•certificate-transparency-trillian-ctserver
< 1.3.3-r7
- chainguard•chainloop-control-plane
< 1.95.0-r0
- chainguard•chainloop-control-plane-fips
< 1.94.1-r1
- chainguard•cloudnative-pg
< 1.29.0-r5
- chainguard•cloudnative-pg-fips
< 1.29.0-r4
- chainguard•cloudnative-pg-fips-plugins
< 1.29.0-r4
- chainguard•cloudnative-pg-plugins
< 1.29.0-r5
- chainguard•cloudprober
< 0.14.2-r9
- chainguard•cloudprober-fips
< 0.14.2-r7
- chainguard•commercial-chainloop-backend
< 1.72.2-r0
- chainguard•commercial-expanso-edge
< 2.1.19-r0
- chainguard•commercial-grafana-11.6
< 11.6.16-r0
- chainguard•commercial-grafana-12.1
all
- chainguard•commercial-grafana-12.2
< 12.2.10-r0
- chainguard•commercial-grafana-12.3
< 12.3.8-r0
- chainguard•commercial-grafana-12.4
< 12.4.5-r0
- chainguard•dapr-daprd-1.14
< 1.14.5-r21
- chainguard•dapr-daprd-1.15
< 1.15.14-r3
- chainguard•dapr-daprd-1.16
< 1.16.14-r1
- chainguard•dapr-daprd-1.17
< 1.17.5-r1
- chainguard•dapr-daprd-fips-1.14
< 1.14.5-r20
- chainguard•dapr-daprd-fips-1.15
< 1.15.14-r2
- chainguard•dapr-daprd-fips-1.16
< 1.16.14-r1
Showing first 50 affected entries in server-rendered view.
References (16)
- https://github.com/jackc/pgx/security/advisories/GHSA-j88v-2chj-qfwx
- https://github.com/jackc/pgx/commit/60644f84918a8af66d14a4b0d865d4edafd955da
- https://github.com/jackc/pgx/releases/tag/v5.9.2
- https://nvd.nist.gov/vuln/detail/CVE-2026-41889
- https://github.com/jackc/pgx
- https://access.redhat.com/errata/RHSA-2026:15856
- https://images.redhat.com/
- https://access.redhat.com/security/cve/CVE-2026-41889
- https://access.redhat.com/security/updates/classification/
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_15856.json
- https://bugzilla.redhat.com/show_bug.cgi?id=2468307
- https://www.cve.org/CVERecord?id=CVE-2026-41889
- https://access.redhat.com/errata/RHSA-2026:16133
- https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_16133.json
- https://security-tracker.debian.org/tracker/CVE-2026-41889
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41889.json