StackRadar

CVE-2026-41889

Low

Advisory

Published 22 Apr 2026In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
2.3
base score, highest
EPSS
0.004
29th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
308
of 17,781 indexed, latest versions
Container images
324
deployed by those charts
Fix available
1 of 3
affected packages

pgx: SQL Injection via placeholder confusion with dollar quoted string literals

Carried by container images the latest versions of 308 of 17,781 indexed charts deploy, on 324 images.

Affected packageAffected versionsFixed inImages
github.com/jackc/pgx/v5golangv5.0.4, v5.2.0, v5.3.0, v5.3.1+17 more5.9.2186
github.com/jackc/pgx/v4golangv4.6.0, v4.7.1, v4.8.1, v4.8.2-0.20200910143026-040df1ccef85+14 moreno fix listed139
github.com/jackc/pgxgolangv3.1.1-0.20180608201956-39bbc98d99d7+incompatible, v3.2.0+incompatible, v3.3.0+incompatible, v3.6.0+incompatible+1 moreno fix listed16
OSV records
GHSA-j88v-2chj-qfwx
Also known as
GO-2026-5004

Charts affected

308 by stars
ChartLatestAffected imagesRadar Score
truefoundry-monitoringtruefoundryVerified publisher0.1.61 of 8See more

truefoundry-monitoring truefoundry 0.1.6

1 of the 8 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
grafana/grafana:12.3.070d9599b186c
github.com/jackc/pgx/v5@v5.7.6
5.9.2

Open the chart page →

4,526
twitter-apptwitter-helm0.1.121 of 8See more

twitter-app twitter-helm 0.1.12

1 of the 8 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
stakkato95/twitter-service-tweets:0.1.18412d8a8cac3
github.com/jackc/pgx/v4@v4.16.0
no fix listed

Open the chart page →

6,132
twenty-crmvictorlane0.0.11 of 3See more

twenty-crm victorlane 0.0.1

1 of the 3 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
twentycrm/twenty-postgres-spilo:latest2f78405a78be
github.com/jackc/pgx@v3.6.0+incompatible
no fix listed

Open the chart page →

13,459
gateway-control-planewallarmVerified publisher0.2.02 of 2See more

gateway-control-plane wallarm 0.2.0

2 of the 2 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
timescale/timescaledb:latest-pg17bc8527e62f70
github.com/jackc/pgx/v5@v5.7.2
5.9.2
wallarm/gateway-control-plane:0.2.0a321bc974a19
github.com/jackc/pgx/v5@v5.8.0
5.9.2

Open the chart page →

1,455
argo-eventswenerme2.4.271 of 1See more

argo-events wenerme 2.4.27

1 of the 1 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/jackc/pgx/v5@v5.7.5
5.9.2

Open the chart page →

969
wexa-studiowexa-studio1.2.03 of 15See more

wexa-studio wexa-studio 1.2.0

3 of the 15 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
hashicorp/vault:1.15.40b01ed3924e6
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
no fix listed
no fix listed
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
github.com/jackc/pgx/v5@v5.7.4
5.9.2
temporalio/server:1.29.1c1e3326b2ce1
github.com/jackc/pgx/v5@v5.7.4
5.9.2

Open the chart page →

14,983
opentelemetry-collectorwikimedia0.62.71 of 1See more

opentelemetry-collector wikimedia 0.62.7

1 of the 1 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
otel/opentelemetry-collector-contrib:0.81.0c6671841470b
github.com/jackc/pgx/v4@v4.18.1
no fix listed

Open the chart page →

2,022
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-41889.

Container imageDigestPackageFixed in
grafana/grafana:11.5.15781759b3d27
github.com/jackc/pgx/v5@v5.7.1
5.9.2

Open the chart page →

9,381

Container images carrying it

324 by charts deploying them

A fixed version is listed for 1 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
github.com/jackc/pgx/v4@v4.18.1
github.com/jackc/pgx/v5@v5.3.1
no fix listed
5.9.2
6
caddy/ingress:v0.2.118d1366fc0e9
github.com/jackc/pgx/v4@v4.18.1
no fix listed
3
ethpandaops/tracoor:latestd8514b9f4c59
github.com/jackc/pgx/v5@v5.4.3
5.9.2
3
grafana/grafana:11.3.0a0f881232a6f
github.com/jackc/pgx/v5@v5.5.5
5.9.2
3
migrate/migrate:latestcc4ad8e19d66
github.com/jackc/pgx/v4@v4.18.2
github.com/jackc/pgx/v5@v5.5.4
no fix listed
5.9.2
3
oryd/hydra:v2.2.02c93beb5e5f2
github.com/jackc/pgx/v4@v4.18.1
no fix listed
3
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
github.com/jackc/pgx/v5@v5.7.2
5.9.2
3
ghcr.io/sigstore/scaffolding/ct_server:v0.7.3166664ba563e7
github.com/jackc/pgx/v5@v5.7.5
5.9.2
3
ghcr.io/sigstore/scaffolding/trillian_log_server5a878e4e4f03
github.com/jackc/pgx/v4@v4.18.3
no fix listed
3
ghcr.io/sigstore/scaffolding/trillian_log_signer28c5ff40963f
github.com/jackc/pgx/v4@v4.18.3
no fix listed
3
quay.io/devtron/clair:4.3.675fb847ac045
github.com/jackc/pgx/v4@v4.13.0
no fix listed
3
quay.io/devtron/kubewatch:09867a9c-419-39288d30a7c640c63
github.com/jackc/pgx/v5@v5.9.0
5.9.2
3
aquasec/kube-bench:v0.8.0ea3e33bc3c4e
github.com/jackc/pgx/v5@v5.5.4
5.9.2
2
crate/crate_adapter:latestb8d89fa5d19b
github.com/jackc/pgx@v3.1.1-0.20180608201956-39bbc98d99d7+incompatible
no fix listed
2
gotify/server:3.1.0be44495e4609
github.com/jackc/pgx/v5@v5.7.6
5.9.2
2
grafana/alloy:v1.8.17790f6f7fbd8
github.com/jackc/pgx/v4@v4.18.2
no fix listed
2
grafana/alloy:v1.12.2f94b1c82957a
github.com/jackc/pgx/v4@v4.18.3
no fix listed
2
grafana/grafana:12.3.12175aaa91c96
github.com/jackc/pgx/v5@v5.7.6
5.9.2
2
grafana/grafana:12.3.39e1e77ade304
github.com/jackc/pgx/v5@v5.8.0
5.9.2
2
grafana/grafana:11.4.0d8ea37798ccc
github.com/jackc/pgx/v5@v5.5.5
5.9.2
2
grafana/grafana:12.4.1e932bd6ed0e0
github.com/jackc/pgx/v5@v5.8.0
5.9.2
2
hashicorp/vault:1.8.34db614d40d0e
github.com/jackc/pgx@v3.3.0+incompatible
no fix listed
2
hashicorp/vault:1.15.26b4e5dadf082
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.18.1
no fix listed
no fix listed
2
hashicorp/vault:1.12.18de4d5f31b38
github.com/jackc/pgx@v3.3.0+incompatible
github.com/jackc/pgx/v4@v4.15.0
no fix listed
no fix listed
2
hoppscotch/hoppscotch:2024.8.2f1da831950b7
github.com/jackc/pgx/v4@v4.18.0
no fix listed
2
lightninglabs/lnd:v0.18.3-betaf86bbec4dfb3
github.com/jackc/pgx/v4@v4.18.2
github.com/jackc/pgx/v5@v5.3.1
no fix listed
5.9.2
2
oryd/kratos:v1.0.0d06fc5845f63
github.com/jackc/pgx/v4@v4.17.2
no fix listed
2
oryd/kratos:v1.3.1fe2428f103a6
github.com/jackc/pgx/v5@v5.6.0
5.9.2
2
oryd/oathkeeper:v0.40.6e8cb9b79a89c
github.com/jackc/pgx/v4@v4.17.2
no fix listed
2
otel/opentelemetry-collector-contrib:0.96.07ef2a2ff46b9
github.com/jackc/pgx/v4@v4.18.1
no fix listed
2
rancher/kine:v0.11.412889bbcd1e8
github.com/jackc/pgx/v5@v5.4.2
5.9.2
2
rookout/controller:latest4451a6f6b8ec
github.com/jackc/pgx/v4@v4.18.1
no fix listed
2
rookout/data-on-prem:latest51c0fce64467
github.com/jackc/pgx/v4@v4.18.1
no fix listed
2
timescale/timescaledb:latest-pg156343bdc87ca1
github.com/jackc/pgx/v5@v5.7.2
5.9.2
2
zhenghaoz/gorse-master:0.4.12033046b432ec
github.com/jackc/pgx/v4@v4.16.1
no fix listed
2
zhenghaoz/gorse-server:0.4.1239c565685b01
github.com/jackc/pgx/v4@v4.16.1
no fix listed
2
zhenghaoz/gorse-worker:0.4.12f7739f64c9b0
github.com/jackc/pgx/v4@v4.16.1
no fix listed
2
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
github.com/jackc/pgx/v5@v5.7.2
5.9.2
2
ghcr.io/nucleuscloud/neosync/api:0.5.41e2abb798f29f
github.com/jackc/pgx/v5@v5.7.2
5.9.2
2
ghcr.io/nucleuscloud/neosync/worker:0.5.4196f42450c5b1
github.com/jackc/pgx/v5@v5.7.2
5.9.2
2
public.ecr.aws/cloudnatix/llmariner/api-usage-cleaner:1.16.0d47f43484055
github.com/jackc/pgx/v5@v5.5.5
5.9.2
2
public.ecr.aws/cloudnatix/llmariner/api-usage-server:1.16.08f9c32b866b0
github.com/jackc/pgx/v5@v5.5.5
5.9.2
2
public.ecr.aws/cloudnatix/llmariner/cluster-manager-server:1.8.0364b3ff0fcb7
github.com/jackc/pgx/v5@v5.5.5
5.9.2
2
public.ecr.aws/cloudnatix/llmariner/cluster-monitor-server:0.10.22d28f9e3eab4
github.com/jackc/pgx/v5@v5.5.5
5.9.2
2
public.ecr.aws/cloudnatix/llmariner/file-manager-server:1.11.0301216788e93
github.com/jackc/pgx/v5@v5.5.5
5.9.2
2
public.ecr.aws/cloudnatix/llmariner/job-manager-server:1.27.0fe9de719f91e
github.com/jackc/pgx/v5@v5.5.5
5.9.2
2
public.ecr.aws/cloudnatix/llmariner/model-manager-server:1.27.0c057dcdd9ef3
github.com/jackc/pgx/v5@v5.5.5
5.9.2
2
public.ecr.aws/cloudnatix/llmariner/user-manager-server:1.27.1628a14449241
github.com/jackc/pgx/v5@v5.5.4
5.9.2
2
quay.io/argoproj/argo-events:v1.9.11fa07b2c9ece6
github.com/jackc/pgx/v5@v5.7.5
5.9.2
2
quay.io/iver-wharf/wharf-api:v5.2.0b736b345437d
github.com/jackc/pgx/v4@v4.15.0
no fix listed
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.