Skip to content

fix(cve): cve-2026-33815 - pgx memory-safety#378

Open
vmrh21 wants to merge 1 commit into
red-hat-data-services:rhoai-3.4from
vmrh21:fix/cve-2026-33815-pgx-rhoai-3-4-attempt-1
Open

fix(cve): cve-2026-33815 - pgx memory-safety#378
vmrh21 wants to merge 1 commit into
red-hat-data-services:rhoai-3.4from
vmrh21:fix/cve-2026-33815-pgx-rhoai-3-4-attempt-1

Conversation

@vmrh21

@vmrh21 vmrh21 commented Apr 21, 2026

Copy link
Copy Markdown

summary

update github.com/jackc/pgx/v5 from v5.7.6 to v5.9.0 to resolve memory-safety vulnerability (cve-2026-33815).

cve details

  • cve id: cve-2026-33815
  • package: github.com/jackc/pgx/v5
  • vulnerable versions: < v5.9.0
  • fixed version: v5.9.0
  • jira: rhoaieng-57067

changes

  • update github.com/jackc/pgx/v5 from v5.7.6 to v5.9.0 in maas-api/go.mod
  • run go mod tidy to update maas-api/go.sum

test results

tests running - will update once completed

test plan

  • govulncheck confirms cve no longer present
  • ci/cd pipeline passes

🤖 generated with claude code

update github.com/jackc/pgx/v5 from v5.7.6 to v5.9.0 to resolve
memory-safety vulnerability.

resolves: rhoaieng-57067

co-authored-by: claude opus 4.6 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant