{"id":"GO-2026-6171","summary":"WITHDRAWN: Malformed RowDescription and DataRow messages cause panics in github.com/lib/pq","details":"(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). github.com/lib/pq decodes attacker-controlled RowDescription and DataRow payloads without validating their structural relationship or encoded value widths required by binary decoders. A malicious PostgreSQL endpoint or active network attacker on an unauthenticated transport can send malformed row responses, causing unrecovered runtime panics while reading query results.","aliases":["CVE-2026-56872"],"modified":"2026-08-19T17:32:58.085661401Z","published":"2026-08-18T16:38:10Z","withdrawn":"2026-08-18T20:22:53Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-6171","review_status":"REVIEWED"},"references":[{"type":"REPORT","url":"https://github.com/golang/vulndb/issues/6171"}],"affected":[{"package":{"name":"github.com/lib/pq","ecosystem":"Go","purl":"pkg:golang/github.com/lib/pq"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/lib/pq","symbols":["Connector.Connect","DialOpen","Driver.Open","NewDialListener","NewListener","NewListenerConn","Open","conn.Ping","rows.Close","rows.Next"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6171.json"}}],"schema_version":"1.9.0"}