All vulnerabilities

GHSA-rgqc-3x5p-6gwg

crates.io · postgres-protocol

Summary

postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service

Advisory details

A malicious or compromised server can return a binary hstore value with an invalid internal length field, causing the client to panic while decoding it.

Applications that connect only to a trusted database are not exposed; the risk applies to clients that may connect to untrusted or user-supplied servers, or whose connection can be intercepted by a man-in-the-middle.

References