StackRadar

CVE-2026-41889

Low

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
308
of 17,781 indexed, latest versions
Container images
324
deployed by those charts
Fix available
1 of 3
affected packages

pgx: SQL Injection via placeholder confusion with dollar quoted string literals

Carried by container images the latest versions of 308 of 17,781 indexed charts deploy, on 324 images.

Affected packageAffected versionsFixed inImages
github.com/jackc/pgx/v5golangv5.0.4, v5.2.0, v5.3.0, v5.3.1+17 more5.9.2186
github.com/jackc/pgx/v4golangv4.6.0, v4.7.1, v4.8.1, v4.8.2-0.20200910143026-040df1ccef85+14 moreno fix listed139
github.com/jackc/pgxgolangv3.1.1-0.20180608201956-39bbc98d99d7+incompatible, v3.2.0+incompatible, v3.3.0+incompatible, v3.6.0+incompatible+1 moreno fix listed16
OSV records
GHSA-j88v-2chj-qfwx
Also known as
GO-2026-5004

Charts affected

308 by stars
ChartLatestAffected imagesRadar Score
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
github.com/jackc/pgx/v5@v5.7.6
5.9.2

Open the chart page →

4,526
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgx/v4@v4.16.0
no fix listed

Open the chart page →

6,132
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgx@v3.6.0+incompatible
no fix listed

Open the chart page →

13,459
gateway-control-planewallarmVerified publisher0.2.02 of 2See more

gateway-control-plane wallarm 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg17bc8527e62f70
github.com/jackc/pgx/v5@v5.7.2
5.9.2
wallarm/gateway-control-plane:0.2.0a321bc974a19
github.com/jackc/pgx/v5@v5.8.0
5.9.2

Open the chart page →

1,455
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/jackc/pgx/v5@v5.7.5
5.9.2

Open the chart page →

969
wexa-studiowexa-studio1.2.03 of 15See more

wexa-studio wexa-studio 1.2.0

3 of the 15 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
no fix listed
no fix listed
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
github.com/jackc/pgx/v5@v5.7.4
5.9.2
temporalio/server:1.29.1c1e3326b2ce1
github.com/jackc/pgx/v5@v5.7.4
5.9.2

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgx/v4@v4.18.1
no fix listed

Open the chart page →

2,022
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
github.com/jackc/pgx/v5@v5.7.1
5.9.2

Open the chart page →

9,381

Container images carrying it

324 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
goharbor/harbor-jobservice:v2.14.3e2b0298e894d
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
goharbor/notary-server-photon:v2.5.3fd91a4a1273f
github.com/jackc/pgx/v4@v4.12.0
no fix listed
1
goharbor/notary-signer-photon:v2.5.3a92b51aa7d6e
github.com/jackc/pgx/v4@v4.12.0
no fix listed
1
gotify/server:2.9.1a3af47067ce6
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
grafana/agent:v0.44.23364714a2f64
github.com/jackc/pgx/v4@v4.18.2
no fix listed
1
grafana/agent:v0.40.3f6cbec9409be
github.com/jackc/pgx/v4@v4.18.1
no fix listed
1
grafana/alloy:v1.5.101a63f4e032c
github.com/jackc/pgx/v4@v4.18.2
no fix listed
1
grafana/alloy:v1.4.306bdcbb51fc2
github.com/jackc/pgx/v4@v4.18.2
no fix listed
1
grafana/alloy:v1.16.384b76d56c594
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
grafana/alloy:v1.11.38c7256f412fe
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
grafana/alloy:v1.1.1c3dac4e26471
github.com/jackc/pgx/v4@v4.18.2
no fix listed
1
grafana/alloy:v1.14.0f50931848bd8
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
grafana/grafana:13.0.10f86bada30d6
github.com/jackc/pgx/v5@v5.8.0
5.9.2
1
grafana/grafana:13.0.1-security-012d1f9ae67c17
github.com/jackc/pgx/v5@v5.8.0
5.9.2
1
grafana/grafana:12.2.22ebef928d7e5
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
grafana/grafana:12.2.135c41e0fd029
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
grafana/grafana:11.2.2-security-01464eac539793
github.com/jackc/pgx/v5@v5.5.5
5.9.2
1
grafana/grafana:11.5.15781759b3d27
github.com/jackc/pgx/v5@v5.7.1
5.9.2
1
grafana/grafana:11.6.062d2b9d20a19
github.com/jackc/pgx/v5@v5.7.2
5.9.2
1
grafana/grafana:12.3.070d9599b186c
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
grafana/grafana:12.2.074144189b384
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
grafana/grafana:11.5.28b37a2f028f1
github.com/jackc/pgx/v5@v5.7.1
5.9.2
1
grafana/grafana:12.1.1a1701c218024
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
grafana/grafana:12.0.2b5b59bfc7561
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
grafana/grafana:12.3.2ba93c9d192e5
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
grafana/grafana:11.3.1fa801ab6e1ae
github.com/jackc/pgx/v5@v5.5.5
5.9.2
1
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
gresearch/armada-executor:latest393aff4aa8f2
github.com/jackc/pgx/v5@v5.8.0
5.9.2
1
gresearch/armada-lookout:latestf5e3226f1d33
github.com/jackc/pgx/v5@v5.8.0
5.9.2
1
gresearch/armada-lookout-ingester:latest3df14cda1855
github.com/jackc/pgx/v5@v5.8.0
5.9.2
1
gresearch/armada-scheduler:latest6141a6213fcb
github.com/jackc/pgx/v5@v5.8.0
5.9.2
1
gresearch/fasttrackml:latest16d1228220fc
github.com/jackc/pgx/v5@v5.5.5
5.9.2
1
hashicorp/boundary:0.15.3339b78b61750
github.com/jackc/pgx/v4@v4.18.3
github.com/jackc/pgx/v5@v5.5.5
no fix listed
5.9.2
1
hashicorp/boundary:0.21.037bf86488b74
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
hashicorp/boundary:0.8.1fb70bd9210ff
github.com/jackc/pgx/v4@v4.14.0
no fix listed
1
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
no fix listed
no fix listed
1
hashicorp/vault:1.14.0b2177a8bfe85
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.15.0
no fix listed
no fix listed
1
hashicorp/vault:1.19.0bbb7f98dc67d
github.com/jackc/pgx/v4@v4.18.3
no fix listed
1
hashicorp/vault:1.8.4dfc3500beb0e
github.com/jackc/pgx@v3.3.0+incompatible
no fix listed
1
headscale/headscale:0.25.1a7a8ae9616bb
github.com/jackc/pgx/v5@v5.7.1
5.9.2
1
headscale/headscale:0.27.1cd37b3001857
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
github.com/jackc/pgx/v4@v4.18.0
no fix listed
1
instill/artifact-backend:b28766ac4a393e601ed
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
instill/mgmt-backend:d0933d4ebe12f77a3f9
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
instill/model-backend:611f0f2e980125e5ba5
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
ispras/svacer:11-2-042aa9fa9f189
github.com/jackc/pgx/v5@v5.7.4
5.9.2
1
juicedata/juicefs-csi-driver:v0.20.043978fc60798
github.com/jackc/pgx/v5@v5.3.1
5.9.2
1
kubeshop/tracetest:v1.7.173d7e3a2db43
github.com/jackc/pgx/v5@v5.4.2
5.9.2
1
kubevious/ui:1.2.16233e84bdd59
github.com/jackc/pgx/v4@v4.14.0
no fix listed
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
github.com/jackc/pgx/v5@v5.5.5
5.9.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.