CRITICALNuGet →
Npgsql vulnerable to SQL Injection via Protocol Message Size Overflow
Npgsql vulnerable to SQL Injection via Protocol Message Size Overflow
Affected packages
- Npgsql— 8.0.0 → 8.0.3
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/npgsql/npgsql/security/advisories/GHSA-x9vc-6hfv-hg8c
- https://nvd.nist.gov/vuln/detail/CVE-2024-32655
- https://github.com/npgsql/npgsql/commit/091655eed0c84e502ab424950c930339d17c1928
- https://github.com/npgsql/npgsql/commit/3183efb2bdcca159c8c2e22af57e18ea8f853cf0
- https://github.com/npgsql/npgsql/commit/67acbe027e28477ac2199e15cfb554bb2ffaf169
- https://github.com/npgsql/npgsql/commit/703d9af8fa48dfe8c0180e36edb8278f34342d7b
- https://github.com/npgsql/npgsql/commit/a22a42d8141d7a3528f43c02c095a409507cf1af
- https://github.com/npgsql/npgsql/commit/e34e2ba8042e666d9af54a1b255fba4d5b11df56
- https://github.com/npgsql/npgsql/commit/f7e7ead0702d776a8f551f5786c4cac2d65c4bc6
- https://www.youtube.com/watch?v=Tfg1B8u1yvE
- https://github.com/npgsql/npgsql/releases/tag/v8.0.3
- https://github.com/npgsql/npgsql/releases/tag/v7.0.7
- https://github.com/npgsql/npgsql/releases/tag/v6.0.11
- https://github.com/npgsql/npgsql/releases/tag/v5.0.18
- https://github.com/npgsql/npgsql/releases/tag/v4.1.13
- https://github.com/npgsql/npgsql/releases/tag/v4.0.14
- https://github.com/npgsql/npgsql/files/14309397/npgsql-protocol-overflow-poc.zip
- https://github.com/npgsql/npgsql/files/14309386/Npgsql.Security.Advisory.pdf
- https://github.com/npgsql/npgsql
Structured record: https://osv.dev/vulnerability/GHSA-x9vc-6hfv-hg8c
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta