PT-2025-25328 · Go-Pg+1 · Go-Pg+1

Published

2025-06-12

·

Updated

2026-01-26

·

CVE-2024-44905

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions go-pg pg version 10.13.0
Description A SQL injection issue was discovered in the component /types/append value.go. This allows for potential SQL injection attacks.
Recommendations For go-pg pg version 10.13.0, consider restricting access to the append value function in the /types/append value.go component until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-44905
GHSA-6XP3-P59P-Q4FJ
GO-2025-3764
OPENSUSE-SU-2025:15405-1
SUSE-SU-2026:0037-1
SUSE-SU-2026:0292-1

Affected Products

Debian
Go-Pg