{"id":"GO-2026-6172","summary":"WITHDRAWN: Backend frame lengths cause pre-validation memory exhaustion in github.com/lib/pq","details":"(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). github.com/lib/pq allocates the backend-declared PostgreSQL frame payload before applying a protocol length bound or a phase-specific message-type check. A malicious server or active network attacker on an unauthenticated connection can send frame headers declaring multi-gigabyte or invalid-phase payloads, forcing large allocations that lead to memory exhaustion and runtime out-of-memory crashes.","aliases":["CVE-2026-56873"],"modified":"2026-08-19T17:30:29.979447037Z","published":"2026-08-18T16:38:10Z","withdrawn":"2026-08-18T20:22:58Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-6172","review_status":"REVIEWED"},"references":[{"type":"REPORT","url":"https://github.com/golang/vulndb/issues/6172"}],"affected":[{"package":{"name":"github.com/lib/pq","ecosystem":"Go","purl":"pkg:golang/github.com/lib/pq"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.0.0"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/lib/pq","symbols":["Connector.Connect","DialOpen","Driver.Open","NewDialListener","NewListener","NewListenerConn","Open","conn.Begin","conn.BeginTx","conn.Commit","conn.Exec","conn.ExecContext","conn.Ping","conn.Prepare","conn.PrepareContext","conn.Query","conn.QueryContext","conn.Rollback","conn.recvMessage","conn.startup","rows.Close","rows.Next","stmt.Close","stmt.Exec","stmt.ExecContext","stmt.Query","stmt.QueryContext"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6172.json"}}],"schema_version":"1.9.0"}