mediumVulnerability
GHSA-rgqc-3x5p-6gwg
A malicious or compromised server can return a binary `hstore` value with an invalid internal length field, causing the client to panic while decoding it. Applications that connect only to a trusted database are not exposed; the risk applies to clients that may connect to untrusted or user-supplied servers, or whose connection can be intercepted by a man-in-the-middle.
Properties
- ghsa_id
- GHSA-rgqc-3x5p-6gwg
- severity
- medium
- summary
- postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service
- cve_id
- GHSA-rgqc-3x5p-6gwg
- is_ghsa_only
- true
- ghsa_published
- 2026-08-24T19:47:49Z
- source_url
- https://github.com/advisories/GHSA-rgqc-3x5p-6gwg
- ghsa_updated
- 2026-08-24T19:47:52Z
Related Entities (5)
VULNERABLE_TO (1)
←[Software]rust/postgres-protocol
AFFECTS (1)
→[Software]rust/postgres-protocol
HAS_WEAKNESS (2)
→[Weakness]Improper Input Validation
→[Weakness]Uncaught Exception
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph