Advisory Database
  • Advisories
  • Dependency Scanning
  1. cargo
  2. ›
  3. postgres-protocol
  4. ›
  5. GHSA-rgqc-3x5p-6gwg

GHSA-rgqc-3x5p-6gwg: postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

August 24, 2026

A malicious or compromised server can return a binary hstore value with an invalid internal length field, causing the client to panic while decoding it.

Applications that connect only to a trusted database are not exposed; the risk applies to clients that may connect to untrusted or user-supplied servers, or whose connection can be intercepted by a man-in-the-middle.

References

  • github.com/advisories/GHSA-rgqc-3x5p-6gwg
  • github.com/rust-postgres/rust-postgres/commit/a7cf84b5c46431cbca9d8ff50508c23f446efa7d
  • github.com/rust-postgres/rust-postgres/releases/tag/postgres-protocol-v0.6.12
  • rustsec.org/advisories/RUSTSEC-2026-0180.html

Code Behaviors & Features

Detect and mitigate GHSA-rgqc-3x5p-6gwg with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 0.6.12

Fixed versions

  • 0.6.12

Solution

Upgrade to version 0.6.12 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Learn more about CVSS

Weakness

  • CWE-20: Improper Input Validation
  • CWE-248: Uncaught Exception

Source file

cargo/postgres-protocol/GHSA-rgqc-3x5p-6gwg.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 25 Aug 2026 00:18:20 +0000.