{"id":"GO-2026-6168","summary":"WITHDRAWN: Unbounded iteration count causes CPU denial of service in github.com/lib/pq/scram","details":"(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). The SCRAM client in github.com/lib/pq/scram accepts an attacker-controlled iteration count with no upper bound and immediately performs that many PBKDF2-style HMAC rounds. A PostgreSQL endpoint or active network attacker can send a valid SCRAM server-first message with a large iteration count (such as i=2147483647), causing client authentication to consume excessive CPU resources before verifying the server signature.","aliases":["CVE-2026-56869"],"modified":"2026-08-19T17:33:33.260587301Z","published":"2026-08-18T16:38:10Z","withdrawn":"2026-08-18T20:22:41Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-6168","review_status":"REVIEWED"},"references":[{"type":"REPORT","url":"https://github.com/golang/vulndb/issues/6168"}],"affected":[{"package":{"name":"github.com/lib/pq","ecosystem":"Go","purl":"pkg:golang/github.com/lib/pq"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.1.0"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/lib/pq/scram","symbols":["Client.Step","NewClient"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6168.json"}}],"schema_version":"1.9.0"}