jackc / jackc/pgx

Documented 3 silent security fixes (GHSA: CWE-306, CWE-319, CWE-248)

Open
#2,578 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
14.3k
Forks
1.1k
Avg merge
6d 9h
Merged PRs (30d)
11

Description

**Not a vulnerability report — these are already fixed.** Documenting previously undisclosed silent fixes found via automated analysis.

1. **Auth Downgrade (CWE-306):** require_auth added to restrict server auth methods — [GHSA-xp64-pqg5-m7q8](https://github.com/canolgun-commits/pgx/security/advisories/GHSA-xp64-pqg5-m7q8)
2. **TLS Leak (CWE-319):** CancelRequest encrypted when TLS used — [GHSA-c8m8-h5m7-vw9h](https://github.com/canolgun-commits/pgx/security/advisories/GHSA-c8m8-h5m7-vw9h)
3. **Panic DoS (CWE-248):** Geometric text returns error instead of panic — [GHSA-m6q6-pmhm-9wcc](https://github.com/canolgun-commits/pgx/security/advisories/GHSA-m6q6-pmhm-9wcc)

CVE IDs requested via GitHub CNA. Tool: bounty-hunter v6.0

Contributor guide

Open the contributing guide

Research direction

No repository file or test is named. Start by reviewing the three linked GHSA advisories and the referenced fixes, then check the repository's existing security documentation and disclosure process. Done means the three silent fixes and any assigned CVE IDs are documented in the appropriate project location.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, postgresql
Domain
databases, documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.