[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-GO-2026-4518":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":14,"duplicates":17,"related":18,"reserved_at":9,"published_at":25,"modified_at":26,"state":9,"summary":27,"references_raw":29,"kevs":40,"epss":9,"epss_history":41,"metrics":42,"affected":43},"GO-2026-4518","Denial of service in github.com/jackc/pgproto3/v2\n\nThe DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.",null,[],[],[],[],[15],{"_key":16},"CVE-2026-32286",[],[19,21,23],{"_key":20},"RHSA-2026:22450",{"_key":22},"RHSA-2026:22714",{"_key":24},"CGA-722J-M72R-CCHJ","2026-03-16T20:27:13Z","2026-03-23T04:52:39.000210Z",{"cisa_kev":28,"cisa_ransomware":28,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[30,36],{"url":31,"sources":32,"tags":34},"https://github.com/jackc/pgx/issues/2507",[33],"osv_go",[35],"REPORT",{"url":37,"sources":38,"tags":39},"https://github.com/golang/vulndb/issues/4518",[33],[35],[],[],[],[44],{"ecosystem":45,"name":46,"vendor":47,"product":48,"cpe_part":9,"purl_type":49,"purl_namespace":47,"purl_name":48,"source":9,"versions":50},"Go","github.com/jackc/pgproto3/v2","github.com/jackc/pgproto3","v2","golang",[51],{"version":52,"is_range":53,"range_type":54,"version_start":55,"version_start_type":56,"version_end":9,"version_end_type":9,"fixed_in":9},"gte2_0_0",true,"semver","2.0.0","including"]