GHSA-j88v-2chj-qfwx
pgx: SQL Injection via placeholder confusion with dollar quoted string literals
Quick fix
GHSA-j88v-2chj-qfwx — github.com/jackc/pgx/v5: upgrade to the fixed version with the command below.
go get github.com/jackc/pgx/v5@v5.9.2Details
### Impact
SQL Injection can occur when:
1. The non-default simple protocol is used. 2. A dollar quoted string literal is used in the SQL query. 3. That string literal contains text that would be would be interpreted as a placeholder outside of a string literal. 4. The value of that placeholder is controllable by the attacker.
e.g.
```go attackValue := `$tag$; drop table canary; --` _, err = tx.Exec(ctx, `select $tag$ $1 $tag$, $1`, pgx.QueryExecModeSimpleProtocol, attackValue) ```
This is unlikely to occur outside of a contrived scenario.
### Patches
The problem is resolved in v5.9.2.
### Workarounds
Do not use the simple protocol to execute queries matching all the above conditions.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for github.com/jackc/pgx/v4 (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/jackc/pgx (go modules). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/jackc/pgx/security/advisories/GHSA-j88v-2chj-qfwx[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-41889[ADVISORY]
- https://github.com/jackc/pgx/commit/60644f84918a8af66d14a4b0d865d4edafd955da[WEB]
- https://github.com/jackc/pgx[PACKAGE]
- https://github.com/jackc/pgx/releases/tag/v5.9.2[WEB]