mediumVulnerability

GHSA-rgqc-3x5p-6gwg

A malicious or compromised server can return a binary `hstore` value with an invalid internal length field, causing the client to panic while decoding it. Applications that connect only to a trusted database are not exposed; the risk applies to clients that may connect to untrusted or user-supplied servers, or whose connection can be intercepted by a man-in-the-middle.

Properties

ghsa_id
GHSA-rgqc-3x5p-6gwg
severity
medium
summary
postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
cve_id
GHSA-rgqc-3x5p-6gwg
is_ghsa_only
true
ghsa_published
2026-08-24T19:47:49Z
source_url
https://github.com/advisories/GHSA-rgqc-3x5p-6gwg
ghsa_updated
2026-08-24T19:47:52Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]rust/postgres-protocol

AFFECTS (1)

[Software]rust/postgres-protocol

HAS_WEAKNESS (2)

[Weakness]Improper Input Validation
[Weakness]Uncaught Exception

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-rgqc-3x5p-6gwg — Ninja Signal Threat Intelligence | Ninja Signal