Documented 3 silent security fixes (GHSA: CWE-306, CWE-319, CWE-248)
- Dominant language
- Go
- Stars
- 14.3k
- Forks
- 1.1k
- Avg merge
- 6d 9h
- Merged PRs (30d)
- 11
Description
**Not a vulnerability report — these are already fixed.** Documenting previously undisclosed silent fixes found via automated analysis.
1. **Auth Downgrade (CWE-306):** require_auth added to restrict server auth methods — [GHSA-xp64-pqg5-m7q8](https://github.com/canolgun-commits/pgx/security/advisories/GHSA-xp64-pqg5-m7q8)
2. **TLS Leak (CWE-319):** CancelRequest encrypted when TLS used — [GHSA-c8m8-h5m7-vw9h](https://github.com/canolgun-commits/pgx/security/advisories/GHSA-c8m8-h5m7-vw9h)
3. **Panic DoS (CWE-248):** Geometric text returns error instead of panic — [GHSA-m6q6-pmhm-9wcc](https://github.com/canolgun-commits/pgx/security/advisories/GHSA-m6q6-pmhm-9wcc)
CVE IDs requested via GitHub CNA. Tool: bounty-hunter v6.0
Contributor guide
Research direction
No repository file or test is named. Start by reviewing the three linked GHSA advisories and the referenced fixes, then check the repository's existing security documentation and disclosure process. Done means the three silent fixes and any assigned CVE IDs are documented in the appropriate project location.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, postgresql
- Domain
- databases, documentation, security
- Issue type
- Documentation
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 38/100