StackRadar

CVE-2026-41889

Low

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
308
of 17,781 indexed, latest versions
Container images
324
deployed by those charts
Fix available
1 of 3
affected packages

pgx: SQL Injection via placeholder confusion with dollar quoted string literals

Carried by container images the latest versions of 308 of 17,781 indexed charts deploy, on 324 images.

Affected packageAffected versionsFixed inImages
github.com/jackc/pgx/v5golangv5.0.4, v5.2.0, v5.3.0, v5.3.1+17 more5.9.2186
github.com/jackc/pgx/v4golangv4.6.0, v4.7.1, v4.8.1, v4.8.2-0.20200910143026-040df1ccef85+14 moreno fix listed139
github.com/jackc/pgxgolangv3.1.1-0.20180608201956-39bbc98d99d7+incompatible, v3.2.0+incompatible, v3.3.0+incompatible, v3.6.0+incompatible+1 moreno fix listed16
OSV records
GHSA-j88v-2chj-qfwx
Also known as
GO-2026-5004

Charts affected

308 by stars
ChartLatestAffected imagesRadar Score
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
github.com/jackc/pgx/v5@v5.7.6
5.9.2

Open the chart page →

4,526
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgx/v4@v4.16.0
no fix listed

Open the chart page →

6,132
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgx@v3.6.0+incompatible
no fix listed

Open the chart page →

13,459
gateway-control-planewallarmVerified publisher0.2.02 of 2See more

gateway-control-plane wallarm 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg17bc8527e62f70
github.com/jackc/pgx/v5@v5.7.2
5.9.2
wallarm/gateway-control-plane:0.2.0a321bc974a19
github.com/jackc/pgx/v5@v5.8.0
5.9.2

Open the chart page →

1,455
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/jackc/pgx/v5@v5.7.5
5.9.2

Open the chart page →

969
wexa-studiowexa-studio1.2.03 of 15See more

wexa-studio wexa-studio 1.2.0

3 of the 15 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
no fix listed
no fix listed
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
github.com/jackc/pgx/v5@v5.7.4
5.9.2
temporalio/server:1.29.1c1e3326b2ce1
github.com/jackc/pgx/v5@v5.7.4
5.9.2

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgx/v4@v4.18.1
no fix listed

Open the chart page →

2,022
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
github.com/jackc/pgx/v5@v5.7.1
5.9.2

Open the chart page →

9,381

Container images carrying it

324 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
github.com/jackc/pgx/v5@v5.9.0
5.9.2
1
public.ecr.aws/k4y9r6y5/kratos:v25.4.0e8014c6c58b6
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
public.ecr.aws/outerbounds/metaflow_metadata_service:v2.4.13f7567ce3419d
github.com/jackc/pgx/v4@v4.17.2
no fix listed
1
public.ecr.aws/perfectscale-io/psc-exporter:v1.0.45-redhat9083e60c38bc
github.com/jackc/pgx/v5@v5.6.0
5.9.2
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
github.com/jackc/pgx/v4@v4.14.0
no fix listed
1
quay.io/argoproj/argocli:v3.7.11577fc18f86ad
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
quay.io/argoproj/argocli:v3.7.16efd1cb89dc1
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
quay.io/argoproj/argocli:v3.5.591b9825f09a8
github.com/jackc/pgx/v4@v4.18.1
no fix listed
1
quay.io/argoproj/argo-events:v1.9.10a83d2699ae53
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
quay.io/argoproj/workflow-controller:v3.7.166388d1b2f08
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
quay.io/argoproj/workflow-controller:v3.5.56ab0da144235
github.com/jackc/pgx/v4@v4.18.1
no fix listed
1
quay.io/argoproj/workflow-controller:v3.7.11c46aa0ded8ed
github.com/jackc/pgx/v5@v5.7.5
5.9.2
1
quay.io/bentoml/yatai:0.4.614b482c1f1b8
github.com/jackc/pgx/v4@v4.13.0
no fix listed
1
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
github.com/jackc/pgx/v4@v4.13.0
no fix listed
1
quay.io/cloudnativetoolkit/cloud-pak-deployer:latest13aaae779248
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
no fix listed
no fix listed
1
quay.io/fiware/vcverifier:6.21.15f9aa6a9c385
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
quay.io/geored/spmm-collector-contrib:1.0.063baf86a49ac
github.com/jackc/pgx/v4@v4.18.1
no fix listed
1
quay.io/harikube/vcluster-pro:0.32.1b741efae8d31
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
quay.io/opstree/grafana:12.4.3b61c1ed2f015
github.com/jackc/pgx/v5@v5.9.1
5.9.2
1
quay.io/projectquay/clair:4.9.023329c3368e4
github.com/jackc/pgx/v5@v5.7.6
5.9.2
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
github.com/jackc/pgx/v5@v5.9.1
5.9.2
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
github.com/jackc/pgx/v4@v4.18.0
no fix listed
1
registry.gitlab.com/shortlink-org/shortlink/bff:latestf2194e526915
github.com/jackc/pgx/v5@v5.8.0
5.9.2
1
registry.gitlab.com/shortlink-org/shortlink/link:latest86d87291ffd4
github.com/jackc/pgx/v5@v5.8.0
5.9.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.