CVE-2026-41889
LowAdvisory
Published 22 Apr 2026In the index since 5 Sept 2026
- Severity
- Low
- worst across findings
- CVSS
- 2.3
- base score, highest
- EPSS
- 0.004
- 29th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 308
- of 17,781 indexed, latest versions
- Container images
- 324
- deployed by those charts
- Fix available
- 1 of 3
- affected packages
pgx: SQL Injection via placeholder confusion with dollar quoted string literals
Carried by container images the latest versions of 308 of 17,781 indexed charts deploy, on 324 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v5.0.4, v5.2.0, v5.3.0, v5.3.1+17 more | 5.9.2 | 186 |
| github.com/ | v4.6.0, v4.7.1, v4.8.1, v4.8.2-0.20200910143026-040df1ccef85+14 more | no fix listed | 139 |
| github.com/ | v3.1.1-0.20180608201956-39bbc98d99d7+incompatible, v3.2.0+incompatible, v3.3.0+incompatible, v3.6.0+incompatible+1 more | no fix listed | 16 |
- OSV records
- GHSA-j88v-2chj-qfwx
- Also known as
- GO-2026-5004
Charts affected
308 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| truefoundry-monitoringtruefoundryVerified publisher | 0.1.6 | 1 of 8See more | 4,526 |
| twitter-apptwitter-helm | 0.1.12 | 1 of 8See more | 6,132 |
| twenty-crmvictorlane | 0.0.1 | 1 of 3See more | 13,459 |
| gateway-control-planewallarmVerified publisher | 0.2.0 | 2 of 2See more | 1,455 |
| argo-eventswenerme | 2.4.27 | 1 of 1See more | 969 |
| wexa-studiowexa-studio | 1.2.0 | 3 of 15See more | 14,983 |
| opentelemetry-collectorwikimedia | 0.62.7 | 1 of 1See more | 2,022 |
| ygdrassil-monitoringygdrassilVerified publisher | 0.4.0 | 1 of 10See more | 9,381 |
Container images carrying it
324 by charts deploying them
A fixed version is listed for 1 of the 3 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| public.ecr.aws/ | ee9d973e3952 | github.com/ | 5.9.2 | 1 |
| public.ecr.aws/ | e8014c6c58b6 | github.com/ | 5.9.2 | 1 |
| public.ecr.aws/ | f7567ce3419d | github.com/ | no fix listed | 1 |
| public.ecr.aws/ | 9083e60c38bc | github.com/ | 5.9.2 | 1 |
| public.ecr.aws/ | 573779e57fae | github.com/ | no fix listed | 1 |
| quay.io/ | 577fc18f86ad | github.com/ | 5.9.2 | 1 |
| quay.io/ | 6efd1cb89dc1 | github.com/ | 5.9.2 | 1 |
| quay.io/ | 91b9825f09a8 | github.com/ | no fix listed | 1 |
| quay.io/ | a83d2699ae53 | github.com/ | 5.9.2 | 1 |
| quay.io/ | 66388d1b2f08 | github.com/ | 5.9.2 | 1 |
| quay.io/ | 6ab0da144235 | github.com/ | no fix listed | 1 |
| quay.io/ | c46aa0ded8ed | github.com/ | 5.9.2 | 1 |
| quay.io/ | 14b482c1f1b8 | github.com/ | no fix listed | 1 |
| quay.io/ | a5dc9d91de0d | github.com/ | no fix listed | 1 |
| quay.io/ | 13aaae779248 | github.com/ github.com/ | no fix listed no fix listed | 1 |
| quay.io/ | 5f9aa6a9c385 | github.com/ | 5.9.2 | 1 |
| quay.io/ | 63baf86a49ac | github.com/ | no fix listed | 1 |
| quay.io/ | b741efae8d31 | github.com/ | 5.9.2 | 1 |
| quay.io/ | b61c1ed2f015 | github.com/ | 5.9.2 | 1 |
| quay.io/ | 23329c3368e4 | github.com/ | 5.9.2 | 1 |
| registry.gitlab.com/ | 5b7636dfba3f | github.com/ | 5.9.2 | 1 |
| registry.gitlab.com/ | f91b602ca572 | github.com/ | no fix listed | 1 |
| registry.gitlab.com/ | f2194e526915 | github.com/ | 5.9.2 | 1 |
| registry.gitlab.com/ | 86d87291ffd4 | github.com/ | 5.9.2 | 1 |