StackRadar

CVE-2026-41889

Low

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
308
of 17,781 indexed, latest versions
Container images
324
deployed by those charts
Fix available
1 of 3
affected packages

pgx: SQL Injection via placeholder confusion with dollar quoted string literals

Carried by container images the latest versions of 308 of 17,781 indexed charts deploy, on 324 images.

Affected packageAffected versionsFixed inImages
github.com/jackc/pgx/v5golangv5.0.4, v5.2.0, v5.3.0, v5.3.1+17 more5.9.2186
github.com/jackc/pgx/v4golangv4.6.0, v4.7.1, v4.8.1, v4.8.2-0.20200910143026-040df1ccef85+14 moreno fix listed139
github.com/jackc/pgxgolangv3.1.1-0.20180608201956-39bbc98d99d7+incompatible, v3.2.0+incompatible, v3.3.0+incompatible, v3.6.0+incompatible+1 moreno fix listed16
OSV records
GHSA-j88v-2chj-qfwx
Also known as
GO-2026-5004

Charts affected

308 by stars
ChartLatestAffected imagesRadar Score
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
github.com/jackc/pgx/v5@v5.7.6
5.9.2

Open the chart page →

4,526
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgx/v4@v4.16.0
no fix listed

Open the chart page →

6,132
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgx@v3.6.0+incompatible
no fix listed

Open the chart page →

13,459
gateway-control-planewallarmVerified publisher0.2.02 of 2See more

gateway-control-plane wallarm 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg17bc8527e62f70
github.com/jackc/pgx/v5@v5.7.2
5.9.2
wallarm/gateway-control-plane:0.2.0a321bc974a19
github.com/jackc/pgx/v5@v5.8.0
5.9.2

Open the chart page →

1,455
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/jackc/pgx/v5@v5.7.5
5.9.2

Open the chart page →

969
wexa-studiowexa-studio1.2.03 of 15See more

wexa-studio wexa-studio 1.2.0

3 of the 15 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
no fix listed
no fix listed
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
github.com/jackc/pgx/v5@v5.7.4
5.9.2
temporalio/server:1.29.1c1e3326b2ce1
github.com/jackc/pgx/v5@v5.7.4
5.9.2

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgx/v4@v4.18.1
no fix listed

Open the chart page →

2,022
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
github.com/jackc/pgx/v5@v5.7.1
5.9.2

Open the chart page →

9,381

Container images carrying it

324 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
alex6021710/ai-scale-auth:latest6c7a47e470c3
github.com/jackc/pgx/v4@v4.10.1
no fix listed
1
alex6021710/ai-scale-migrator:latest744b8a924f35
github.com/jackc/pgx/v4@v4.10.1
no fix listed
1
almorgv/gitlab-code-review-notifier:0.1.25f2a7d2b44d8
github.com/jackc/pgx@v3.6.2+incompatible
no fix listed
1
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
github.com/jackc/pgx/v5@v5.3.1
5.9.2
1
apecloud/kb-cloud-installer:v2.1.42-certified98abc64aa985
github.com/jackc/pgx/v4@v4.18.3
github.com/jackc/pgx/v5@v5.7.4
no fix listed
5.9.2
1
aquasec/kube-bench:v0.6.176672264accce
github.com/jackc/pgx/v5@v5.2.0
5.9.2
1
aquasec/kube-bench:v0.15.07a8fa32dce21
github.com/jackc/pgx/v5@v5.6.0
5.9.2
1
aquasec/kube-bench:v0.6.9c329d73fea58
github.com/jackc/pgx/v4@v4.16.1
no fix listed
1
artifacthub/db-migrator:v1.23.028c13565ac5c
github.com/jackc/pgx/v4@v4.7.1
no fix listed
1
artifacthub/db-migrator:v1.19.02a746b289fcd
github.com/jackc/pgx/v4@v4.7.1
no fix listed
1
artifacthub/hub:v1.19.0111918d8c399
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
artifacthub/hub:v1.23.07d3a91c539dc
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
artifacthub/scanner:v1.23.02d8365601f0e
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
artifacthub/scanner:v1.19.0323d026e78c3
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
artifacthub/tracker:v1.23.05368d21a6e5c
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
artifacthub/tracker:v1.19.06596c8c4d955
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
baserow/baserow:1.30.1df0c42eb67e8
github.com/jackc/pgx/v4@v4.18.0
no fix listed
1
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
github.com/jackc/pgx/v5@v5.5.5
5.9.2
1
burningalchemist/sql_exporter:0.16.0b8e4757c7def
github.com/jackc/pgx/v5@v5.7.1
5.9.2
1
bytesafe/bytesafe-ce:v1.0.4ee287384c005
github.com/jackc/pgx/v4@v4.18.1
no fix listed
1
cockroachdb/cockroach-operator:v2.1.0983312754620
github.com/jackc/pgx@v3.6.2+incompatible
no fix listed
1
dollarshaveclub/furan2:master14a257836529
github.com/jackc/pgx/v4@v4.8.1
no fix listed
1
donetick/donetick:v0.1.60849a43d9e363
github.com/jackc/pgx/v5@v5.5.4
5.9.2
1
dragonflyoss/manager:v2.1.49c3ef7f10698d
github.com/jackc/pgx/v5@v5.5.4
5.9.2
1
dragonflyoss/scheduler:v2.1.49523785c77787
github.com/jackc/pgx/v5@v5.5.4
5.9.2
1
drorivry4/rego:lateste035d49b15ca
github.com/jackc/pgx/v5@v5.4.3
5.9.2
1
emqx/ecp-main:2.5.1fa876f71e5d6
github.com/jackc/pgx/v5@v5.5.5
5.9.2
1
ethpandaops/armiarma:master1a9c3264f0a9
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
ethpandaops/dora:master2381ea793a12
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
ethpandaops/forky:debian-latestc937f4ba737c
github.com/jackc/pgx/v5@v5.5.2
5.9.2
1
factly/dega-api:0.15.166fafc7b0a17
github.com/jackc/pgx/v4@v4.10.1
no fix listed
1
factly/dega-server:0.15.194d21479382e
github.com/jackc/pgx/v4@v4.10.1
no fix listed
1
factly/kavach-server:0.22.3be85ff1b9bd3
github.com/jackc/pgx/v4@v4.10.1
no fix listed
1
factly/mande-server:0.34.1384d384310ef
github.com/jackc/pgx/v4@v4.10.1
no fix listed
1
factly/vidcheck-server:0.12.087064eb0463c
github.com/jackc/pgx/v4@v4.9.0
no fix listed
1
falcosecurity/falcosidekick:2.32.01976da721518
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
falcosecurity/falcosidekick:2.27.0828ee36cb13a
github.com/jackc/pgx/v5@v5.0.4
5.9.2
1
flanksource/apm-hub:v0.0.471dacc3195bf9
github.com/jackc/pgx/v5@v5.4.3
5.9.2
1
flanksource/batch-runner:v1.0.44689687a7cf95
github.com/jackc/pgx/v4@v4.18.3
github.com/jackc/pgx/v5@v5.7.6
no fix listed
5.9.2
1
flashcatcloud/categraf:latest42e6ab16472e
github.com/jackc/pgx/v4@v4.18.2
no fix listed
1
flashcatcloud/nightingale:8.5.1421acb36181b
github.com/jackc/pgx/v5@v5.7.1
5.9.2
1
gboxproxy/gbox:v1.0.63a9f4a711d5c
github.com/jackc/pgx/v4@v4.14.0
no fix listed
1
goalert/goalert:v0.32.008d57388b0cb
github.com/jackc/pgx/v5@v5.5.3
5.9.2
1
gobitfly/eth2-beaconchain-explorer:latest1d08a7986348
github.com/jackc/pgx/v5@v5.4.3
5.9.2
1
goharbor/harbor-core:v2.9.06412d679fdc3
github.com/jackc/pgx/v4@v4.18.1
no fix listed
1
goharbor/harbor-core:v2.5.386bf3031f4a7
github.com/jackc/pgx/v4@v4.12.0
no fix listed
1
goharbor/harbor-core:v2.14.3a30e5a8be3d9
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
goharbor/harbor-core:v2.11.1c017dd84ee96
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
goharbor/harbor-jobservice:v2.9.039435daedd0c
github.com/jackc/pgx/v4@v4.18.1
no fix listed
1
goharbor/harbor-jobservice:v2.5.38d5339ff2d74
github.com/jackc/pgx/v4@v4.12.0
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.