{"id":"GO-2026-6173","summary":"WITHDRAWN: Pre-protocol error reader permits unbounded memory consumption in github.com/lib/pq","details":"(This report has been withdrawn with reason: \"Report mistakenly added without having CVE / GHSA associated\"). The special-case parser for PostgreSQL pre-protocol plain-text errors in github.com/lib/pq calls bufio.Reader.ReadString(0) without a byte limit. A malicious PostgreSQL endpoint or active network attacker on an unauthenticated transport can send an error message response with non-NUL bytes continuously, causing the client to buffer an arbitrarily large string and crash with an unrecoverable out-of-memory error.","aliases":["CVE-2026-56874"],"modified":"2026-08-19T17:32:58.130253348Z","published":"2026-08-18T16:38:10Z","withdrawn":"2026-08-18T20:23:02Z","database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-6173","review_status":"REVIEWED"},"references":[{"type":"REPORT","url":"https://github.com/golang/vulndb/issues/6173"}],"affected":[{"package":{"name":"github.com/lib/pq","ecosystem":"Go","purl":"pkg:golang/github.com/lib/pq"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.11.0"}]}],"ecosystem_specific":{"imports":[{"symbols":["Connector.Connect","DialOpen","Driver.Open","NewDialListener","NewListener","NewListenerConn","Open","conn.Begin","conn.BeginTx","conn.Commit","conn.Exec","conn.ExecContext","conn.Ping","conn.Prepare","conn.PrepareContext","conn.Query","conn.QueryContext","conn.Rollback","conn.recvMessage","rows.Close","rows.Next","stmt.Close","stmt.Exec","stmt.ExecContext","stmt.Query","stmt.QueryContext"],"path":"github.com/lib/pq"}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-6173.json"}}],"schema_version":"1.9.0"}