Skip to content

Bump github.com/jackc/pgx/v5 to v5.9.2 + Go 1.26.1 (CVE-2026-41889) #607

@kaidaguerre

Description

@kaidaguerre

CVE-2026-41889 / GHSA-j88v-2chj-qfwx — SQL injection in github.com/jackc/pgx/v5, fixed in v5.9.2. Vanta-flagged, ~2-day SLA (2026-05-18 report).

This repo: pgx v5.6.0 (indirect). Also requires Go toolchain bump 1.24 → 1.26.1 — pgx v5.9.x requires Go >=1.25.

Fix: bump Go pins + go get github.com/jackc/pgx/v5@v5.9.2 && go mod tidy. Patch the active release line v0.7.x and main.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions