CVE-2026-4427 PUBLISHED

Github.com/jackc/pgproto3: pgproto3: denial of service via negative field length in datarow message

Assigner: redhat
Reserved: 19.03.2026 Published: 19.03.2026 Updated: 19.03.2026

A flaw was found in pgproto3. A malicious or compromised PostgreSQL server can exploit this by sending a DataRow message with a negative field length. This input validation vulnerability can lead to a denial of service (DoS) due to a slice bounds out of range panic.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor Red Hat
Product Assisted Installer for Red Hat OpenShift Container Platform 2
Versions Default: affected
Vendor Red Hat
Product Assisted Installer for Red Hat OpenShift Container Platform 2
Versions Default: affected
Vendor Red Hat
Product Multicluster Engine for Kubernetes
Versions Default: affected
Vendor Red Hat
Product Multicluster Engine for Kubernetes
Versions Default: affected
Vendor Red Hat
Product Multicluster Engine for Kubernetes
Versions Default: affected
Vendor Red Hat
Product Multicluster Engine for Kubernetes
Versions Default: affected
Vendor Red Hat
Product Multicluster Engine for Kubernetes
Versions Default: affected
Vendor Red Hat
Product Multicluster Engine for Kubernetes
Versions Default: affected
Vendor Red Hat
Product Multicluster Engine for Kubernetes
Versions Default: affected
Vendor Red Hat
Product Multicluster Engine for Kubernetes
Versions Default: affected
Vendor Red Hat
Product Multicluster Engine for Kubernetes
Versions Default: affected
Vendor Red Hat
Product Multicluster Global Hub
Versions Default: affected
Vendor Red Hat
Product Multicluster Global Hub
Versions Default: affected
Vendor Red Hat
Product Multicluster Global Hub
Versions Default: affected
Vendor Red Hat
Product Multicluster Global Hub
Versions Default: affected
Vendor Red Hat
Product Multicluster Global Hub
Versions Default: affected
Vendor Red Hat
Product Red Hat Advanced Cluster Management for Kubernetes 2
Versions Default: affected
Vendor Red Hat
Product Red Hat Advanced Cluster Management for Kubernetes 2
Versions Default: affected
Vendor Red Hat
Product Red Hat Advanced Cluster Security 4
Versions Default: affected
Vendor Red Hat
Product Red Hat Advanced Cluster Security 4
Versions Default: affected
Vendor Red Hat
Product Red Hat Advanced Cluster Security 4
Versions Default: affected
Vendor Red Hat
Product Red Hat Advanced Cluster Security 4
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 10
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 8
Versions Default: affected
Vendor Red Hat
Product Red Hat Enterprise Linux 9
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift AI (RHOAI)
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift AI (RHOAI)
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift AI (RHOAI)
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Cluster Manager CLI
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift Container Platform 4
Versions Default: affected
Vendor Red Hat
Product Red Hat OpenShift on AWS
Versions Default: affected
Vendor Red Hat
Product Red Hat Quay 3
Versions Default: affected
Vendor Red Hat
Product Red Hat Quay 3
Versions Default: affected
Vendor Red Hat
Product Red Hat Quay 3
Versions Default: affected
Vendor Red Hat
Product Red Hat Quay 3
Versions Default: affected
Vendor Red Hat
Product Red Hat Quay 3
Versions Default: affected
Vendor Red Hat
Product Red Hat Quay 3
Versions Default: affected
Vendor Red Hat
Product Red Hat Trusted Artifact Signer
Versions Default: affected
Vendor Red Hat
Product Red Hat Trusted Artifact Signer
Versions Default: affected
Vendor Red Hat
Product Red Hat Trusted Artifact Signer
Versions Default: affected
Vendor Red Hat
Product Red Hat Trusted Artifact Signer
Versions Default: affected
Vendor Red Hat
Product Red Hat Trusted Artifact Signer
Versions Default: affected

References

Problem Types

  • Improper Validation of Array Index CWE