CVE-2026-33816
CriticalAdvisory
Published 7 Apr 2026In the index since 5 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.8
- base score, highest
- EPSS
- 0.006
- 45th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 182
- of 17,781 indexed, latest versions
- Container images
- 180
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Memory-safety vulnerability in github.com/jackc/pgx/v5.
Carried by container images the latest versions of 182 of 17,781 indexed charts deploy, on 180 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v5.0.4, v5.2.0, v5.3.0, v5.3.1+15 more | 5.9.0 | 180 |
- OSV records
- GHSA-9jj7-4m8r-rfcm
- Also known as
- GO-2026-4772
Charts affected
182 by stars
Container images carrying it
180 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| quay.io/ | fbeaef7a8566 | github.com/ | 5.9.0 | 6 |
| ethpandaops/ | d8514b9f4c59 | github.com/ | 5.9.0 | 3 |
| grafana/ | a0f881232a6f | github.com/ | 5.9.0 | 3 |
| migrate/ | cc4ad8e19d66 | github.com/ | 5.9.0 | 3 |
| ghcr.io/ | a27779ed1085 | github.com/ | 5.9.0 | 3 |
| ghcr.io/ | 66664ba563e7 | github.com/ | 5.9.0 | 3 |
| aquasec/ | ea3e33bc3c4e | github.com/ | 5.9.0 | 2 |
| gotify/ | be44495e4609 | github.com/ | 5.9.0 | 2 |
| grafana/ | 2175aaa91c96 | github.com/ | 5.9.0 | 2 |
| grafana/ | 9e1e77ade304 | github.com/ | 5.9.0 | 2 |
| grafana/ | d8ea37798ccc | github.com/ | 5.9.0 | 2 |
| grafana/ | e932bd6ed0e0 | github.com/ | 5.9.0 | 2 |
| lightninglabs/ | f86bbec4dfb3 | github.com/ | 5.9.0 | 2 |
| oryd/ | fe2428f103a6 | github.com/ | 5.9.0 | 2 |
| rancher/ | 12889bbcd1e8 | github.com/ | 5.9.0 | 2 |
| timescale/ | 6343bdc87ca1 | github.com/ | 5.9.0 | 2 |
| ghcr.io/ | b5210df46c05 | github.com/ | 5.9.0 | 2 |
| ghcr.io/ | e2abb798f29f | github.com/ | 5.9.0 | 2 |
| ghcr.io/ | 96f42450c5b1 | github.com/ | 5.9.0 | 2 |
| public.ecr.aws/ | d47f43484055 | github.com/ | 5.9.0 | 2 |
| public.ecr.aws/ | 8f9c32b866b0 | github.com/ | 5.9.0 | 2 |
| public.ecr.aws/ | 364b3ff0fcb7 | github.com/ | 5.9.0 | 2 |
| public.ecr.aws/ | 2d28f9e3eab4 | github.com/ | 5.9.0 | 2 |
| public.ecr.aws/ | 301216788e93 | github.com/ | 5.9.0 | 2 |
| public.ecr.aws/ | fe9de719f91e | github.com/ | 5.9.0 | 2 |
| public.ecr.aws/ | c057dcdd9ef3 | github.com/ | 5.9.0 | 2 |
| public.ecr.aws/ | 628a14449241 | github.com/ | 5.9.0 | 2 |
| quay.io/ | fa07b2c9ece6 | github.com/ | 5.9.0 | 2 |
| apache/ | ffe68d6b99c0 | github.com/ | 5.9.0 | 1 |
| apecloud/ | 98abc64aa985 | github.com/ | 5.9.0 | 1 |
| aquasec/ | 6672264accce | github.com/ | 5.9.0 | 1 |
| aquasec/ | 7a8fa32dce21 | github.com/ | 5.9.0 | 1 |
| bitnamilegacy/ | cb8ab5515676 | github.com/ | 5.9.0 | 1 |
| burningalchemist/ | b8e4757c7def | github.com/ | 5.9.0 | 1 |
| donetick/ | 849a43d9e363 | github.com/ | 5.9.0 | 1 |
| dragonflyoss/ | c3ef7f10698d | github.com/ | 5.9.0 | 1 |
| dragonflyoss/ | 523785c77787 | github.com/ | 5.9.0 | 1 |
| drorivry4/ | e035d49b15ca | github.com/ | 5.9.0 | 1 |
| emqx/ | fa876f71e5d6 | github.com/ | 5.9.0 | 1 |
| ethpandaops/ | c937f4ba737c | github.com/ | 5.9.0 | 1 |
| falcosecurity/ | 1976da721518 | github.com/ | 5.9.0 | 1 |
| falcosecurity/ | 828ee36cb13a | github.com/ | 5.9.0 | 1 |
| flanksource/ | 1dacc3195bf9 | github.com/ | 5.9.0 | 1 |
| flanksource/ | 689687a7cf95 | github.com/ | 5.9.0 | 1 |
| flashcatcloud/ | 421acb36181b | github.com/ | 5.9.0 | 1 |
| goalert/ | 08d57388b0cb | github.com/ | 5.9.0 | 1 |
| gobitfly/ | 1d08a7986348 | github.com/ | 5.9.0 | 1 |
| gotify/ | a3af47067ce6 | github.com/ | 5.9.0 | 1 |
| grafana/ | 0f86bada30d6 | github.com/ | 5.9.0 | 1 |
| grafana/ | 2d1f9ae67c17 | github.com/ | 5.9.0 | 1 |