Skip to content

security: update pgx v5 to v5.10.0 to fix auth downgrade vulnerability (CWE-306)#171611

Open
nkar123412-hub wants to merge 1 commit into
cockroachdb:masterfrom
nkar123412-hub:fix/pgx-auth-downgrade
Open

security: update pgx v5 to v5.10.0 to fix auth downgrade vulnerability (CWE-306)#171611
nkar123412-hub wants to merge 1 commit into
cockroachdb:masterfrom
nkar123412-hub:fix/pgx-auth-downgrade

Conversation

@nkar123412-hub

Copy link
Copy Markdown

This PR updates the dependency from to to resolve a critical authentication downgrade vulnerability (CWE-306).

Fixes #171598

@blathers-crl

blathers-crl Bot commented Jun 12, 2026

Copy link
Copy Markdown

Thank you for contributing to CockroachDB. Please ensure you have followed the guidelines for creating a PR.

Before a member of our team reviews your PR, I have some potential action items for you:

  • Please ensure your git commit message contains a release note.
  • When CI has completed, please ensure no errors have appeared.

I have added a few people who may be able to assist in reviewing:

🦉 Hoot! I am a Blathers, a bot for CockroachDB. My owner is dev-inf.

@blathers-crl blathers-crl Bot added O-community Originated from the community X-blathers-triaged blathers was able to find an owner labels Jun 12, 2026
@blathers-crl blathers-crl Bot requested a review from bghal June 12, 2026 21:24
@cockroachlabs-cla-agent

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


Hermes Agent seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

O-community Originated from the community X-blathers-triaged blathers was able to find an owner

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Dependency: pgx v5.7.2 vulnerable to auth downgrade (CWE-306, fix in v5.10.0)

1 participant