{"id":"GHSA-3gjw-f78c-vvpw","summary":"tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service","details":"A malicious or compromised server can send a row containing fewer fields than\nits row description declares columns. Reading one of the missing columns then\npanics with an out-of-bounds index, aborting the calling task. This affects even\nthe otherwise non-panicking `try_get`, and both `Row` and `SimpleQueryRow`.\n\nApplications that connect only to a trusted database are not exposed; the risk\napplies to clients that may connect to untrusted or user-supplied servers, or\nwhose connection can be intercepted by a man-in-the-middle.","aliases":["RUSTSEC-2026-0178"],"modified":"2026-08-25T02:55:59.557390596Z","published":"2026-08-24T19:49:17Z","database_specific":{"github_reviewed_at":"2026-08-24T19:49:17Z","nvd_published_at":null,"cwe_ids":["CWE-125"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/rust-postgres/rust-postgres/commit/7a00ffa9ad4d951ec0a4564b52f1780fa9d353c1"},{"type":"PACKAGE","url":"https://github.com/rust-postgres/rust-postgres"},{"type":"WEB","url":"https://github.com/rust-postgres/rust-postgres/releases/tag/tokio-postgres-v0.7.18"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0178.html"}],"affected":[{"package":{"name":"tokio-postgres","ecosystem":"crates.io","purl":"pkg:cargo/tokio-postgres"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.4.0"},{"fixed":"0.7.18"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-3gjw-f78c-vvpw/GHSA-3gjw-f78c-vvpw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}