THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rgqc-3x5p-6gwg (medium) — postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

[GHSA] GHSA-rgqc-3x5p-6gwg (medium) — postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

medgithub_advisoriesPublished 2026-08-24

GHSA-rgqc-3x5p-6gwg Severity: medium CVE: None

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

A malicious or compromised server can return a binary `hstore` value with an invalid internal length field, causing the client to panic while decoding it.

Applications that connect only to a trusted database are not exposed; the risk applies to clients that may co

Original source: https://github.com/advisories/GHSA-rgqc-3x5p-6gwg