{
  "threat_severity" : "Moderate",
  "public_date" : "2026-05-08T15:53:00Z",
  "bugzilla" : {
    "description" : "github.com/jackc/pgx: golang: pgx: SQL injection via specific SQL query conditions",
    "id" : "2468307",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2468307"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.9",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-89",
  "details" : [ "pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker. This issue has been patched in version 5.9.2.", "A flaw was found in pgx, a PostgreSQL driver and toolkit for Go. This SQL injection vulnerability can occur when using the non-default simple protocol, a dollar-quoted string literal in the SQL query, and when that string literal contains text interpreted as a placeholder with an attacker-controlled value. An attacker could potentially manipulate SQL queries, leading to a low impact on data integrity." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-05-09T00:00:00Z",
    "advisory" : "RHSA-2026:15856",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "go-fdo-server-main-1.0.1-0.2.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-05-12T00:00:00Z",
    "advisory" : "RHSA-2026:16133",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "caddy-main-2.11.3-0.1.hum1"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-06-10T00:00:00Z",
    "advisory" : "RHSA-2026:25138",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "cosign-main-3.1.1-0.1.hum1"
  } ],
  "package_state" : [ {
    "product_name" : "Assisted Installer for Red Hat OpenShift Container Platform 2",
    "fix_state" : "Fix deferred",
    "package_name" : "rhai/assisted-installer-agent-rhel9",
    "cpe" : "cpe:/a:redhat:assisted_installer:2"
  }, {
    "product_name" : "Assisted Installer for Red Hat OpenShift Container Platform 2",
    "fix_state" : "Fix deferred",
    "package_name" : "rhai/assisted-installer-controller-rhel9",
    "cpe" : "cpe:/a:redhat:assisted_installer:2"
  }, {
    "product_name" : "Assisted Installer for Red Hat OpenShift Container Platform 2",
    "fix_state" : "Fix deferred",
    "package_name" : "rhai/assisted-installer-rhel9",
    "cpe" : "cpe:/a:redhat:assisted_installer:2"
  }, {
    "product_name" : "Cryostat 4",
    "fix_state" : "Fix deferred",
    "package_name" : "cryostat/cryostat-storage-rhel9",
    "cpe" : "cpe:/a:redhat:cryostat:4"
  }, {
    "product_name" : "Custom Metric Autoscaler operator for Red Hat Openshift",
    "fix_state" : "Fix deferred",
    "package_name" : "custom-metrics-autoscaler/custom-metrics-autoscaler-adapter-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
  }, {
    "product_name" : "Custom Metric Autoscaler operator for Red Hat Openshift",
    "fix_state" : "Fix deferred",
    "package_name" : "custom-metrics-autoscaler/custom-metrics-autoscaler-admission-webhooks-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
  }, {
    "product_name" : "Custom Metric Autoscaler operator for Red Hat Openshift",
    "fix_state" : "Fix deferred",
    "package_name" : "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
  }, {
    "product_name" : "Custom Metric Autoscaler operator for Red Hat Openshift",
    "fix_state" : "Fix deferred",
    "package_name" : "custom-metrics-autoscaler/custom-metrics-autoscaler-rhel9-operator",
    "cpe" : "cpe:/a:redhat:openshift_custom_metrics_autoscaler:2"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-engine/assisted-installer-agent-rhel8",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-engine/assisted-installer-agent-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-engine/assisted-installer-controller-rhel8",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-engine/assisted-installer-controller-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-engine/assisted-installer-rhel8",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-engine/assisted-installer-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-engine/assisted-service-8-rhel8",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-engine/assisted-service-9-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-engine/azure-service-operator-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Engine for Kubernetes",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-engine/cluster-api-provider-aws-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_engine"
  }, {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-agent-rhel8",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-agent-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-grafana-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-kessel-inventory-api-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-manager-rhel8",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-manager-rhel9",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-operator-bundle",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-rhel8-operator",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Fix deferred",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-rhel9-operator",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-pipelines/pipelines-hub-api-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-pipelines/pipelines-hub-api-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-pipelines/pipelines-hub-db-migration-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-pipelines/pipelines-hub-db-migration-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-pipelines/pipelines-results-api-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-pipelines/pipelines-results-api-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Pipelines",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-pipelines/pipelines-results-retention-policy-agent-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_pipelines:1"
  }, {
    "product_name" : "OpenShift Service Mesh 2",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-service-mesh/istio-rhel8-operator",
    "cpe" : "cpe:/a:redhat:service_mesh:2"
  }, {
    "product_name" : "Red Hat 3scale API Management Platform 2",
    "fix_state" : "Fix deferred",
    "package_name" : "3scale-amp2/3scale-operator-bundle",
    "cpe" : "cpe:/a:redhat:red_hat_3scale_amp:2"
  }, {
    "product_name" : "Red Hat 3scale API Management Platform 2",
    "fix_state" : "Fix deferred",
    "package_name" : "3scale-amp2/3scale-rhel7-operator",
    "cpe" : "cpe:/a:redhat:red_hat_3scale_amp:2"
  }, {
    "product_name" : "Red Hat 3scale API Management Platform 2",
    "fix_state" : "Fix deferred",
    "package_name" : "3scale-amp2/3scale-rhel9-operator",
    "cpe" : "cpe:/a:redhat:red_hat_3scale_amp:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Fix deferred",
    "package_name" : "rhacm2/acm-grafana-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Fix deferred",
    "package_name" : "rhacm2/acm-search-indexer-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Fix deferred",
    "package_name" : "rhacm2/acm-search-v2-api-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4",
    "fix_state" : "Fix deferred",
    "package_name" : "advanced-cluster-security/rhacs-main-rhel8",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4",
    "fix_state" : "Fix deferred",
    "package_name" : "advanced-cluster-security/rhacs-rhel8-operator",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4",
    "fix_state" : "Fix deferred",
    "package_name" : "advanced-cluster-security/rhacs-roxctl-rhel8",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4"
  }, {
    "product_name" : "Red Hat Advanced Cluster Security 4",
    "fix_state" : "Fix deferred",
    "package_name" : "advanced-cluster-security/rhacs-scanner-v4-rhel8",
    "cpe" : "cpe:/a:redhat:advanced_cluster_security:4"
  }, {
    "product_name" : "Red Hat Ceph Storage 6",
    "fix_state" : "Fix deferred",
    "package_name" : "rhceph/rhceph-6-dashboard-rhel9",
    "cpe" : "cpe:/a:redhat:ceph_storage:6"
  }, {
    "product_name" : "Red Hat Ceph Storage 8",
    "fix_state" : "Fix deferred",
    "package_name" : "rhceph/grafana-rhel9",
    "cpe" : "cpe:/a:redhat:ceph_storage:8"
  }, {
    "product_name" : "Red Hat Ceph Storage 9",
    "fix_state" : "Fix deferred",
    "package_name" : "rhceph/alloy-rhel10",
    "cpe" : "cpe:/a:redhat:ceph_storage:9"
  }, {
    "product_name" : "Red Hat Ceph Storage 9",
    "fix_state" : "Fix deferred",
    "package_name" : "rhceph/grafana-rhel10",
    "cpe" : "cpe:/a:redhat:ceph_storage:9"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "flightctl",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-alert-exporter-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-alert-exporter-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-alertmanager-proxy-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-alertmanager-proxy-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-api-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-api-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-cli-artifacts-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-cli-artifacts-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-db-setup-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-db-setup-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-imagebuilder-api-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-imagebuilder-api-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-imagebuilder-worker-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-imagebuilder-worker-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-pam-issuer-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-pam-issuer-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-periodic-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-periodic-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-telemetry-gateway-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-telemetry-gateway-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-userinfo-proxy-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-userinfo-proxy-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-worker-rhel10",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Edge Manager 1",
    "fix_state" : "Fix deferred",
    "package_name" : "rhem/flightctl-worker-rhel9",
    "cpe" : "cpe:/a:redhat:edge_manager:1"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Fix deferred",
    "package_name" : "go-fdo-server",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Fix deferred",
    "package_name" : "osbuild-composer",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "osbuild-composer",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Fix deferred",
    "package_name" : "osbuild-composer",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-codeflare-operator-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-codeflare-operator-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-data-science-pipelines-argo-argoexec-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-data-science-pipelines-argo-workflowcontroller-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-maas-api-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-ml-pipelines-api-server-v2-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-ml-pipelines-api-server-v2-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-ml-pipelines-driver-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-ml-pipelines-driver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-ml-pipelines-launcher-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-ml-pipelines-launcher-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-ml-pipelines-persistenceagent-v2-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-ml-pipelines-scheduledworkflow-v2-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-mod-arch-model-registry-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift AI (RHOAI)",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoai/odh-model-registry-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_ai"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/azure-service-rhel9-operator",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/o-cloud-manager-operator-bundle",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/o-cloud-manager-rhel9-operator",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/oc-mirror-plugin-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-agent-installer-api-server-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-agent-installer-api-server-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-agent-installer-csr-approver-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-agent-installer-csr-approver-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-agent-installer-node-agent-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-agent-installer-node-agent-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-agent-installer-orchestrator-rhel8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-agent-installer-orchestrator-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-aws-cluster-api-controllers-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-baremetal-installer-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-cluster-control-plane-machine-set-rhel9-operator",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift4/ose-installer-rhel9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat Openshift Data Foundation 4",
    "fix_state" : "Fix deferred",
    "package_name" : "odf4/odf-cloudnative-pg-rhel9-operator",
    "cpe" : "cpe:/a:redhat:openshift_data_foundation:4"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/argocd-rhel8",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenShift GitOps",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift-gitops-1/argocd-rhel9",
    "cpe" : "cpe:/a:redhat:openshift_gitops:1"
  }, {
    "product_name" : "Red Hat OpenStack Platform 18.0",
    "fix_state" : "Fix deferred",
    "package_name" : "rhoso-operators/openstack-operator-bundle",
    "cpe" : "cpe:/a:redhat:openstack:18.0"
  }, {
    "product_name" : "Red Hat Quay 3",
    "fix_state" : "Fix deferred",
    "package_name" : "quay/clair-rhel8",
    "cpe" : "cpe:/a:redhat:quay:3"
  }, {
    "product_name" : "Red Hat Quay 3",
    "fix_state" : "Fix deferred",
    "package_name" : "quay/clair-rhel9",
    "cpe" : "cpe:/a:redhat:quay:3"
  }, {
    "product_name" : "Red Hat Quay 3",
    "fix_state" : "Fix deferred",
    "package_name" : "quay/quay-operator-rhel8",
    "cpe" : "cpe:/a:redhat:quay:3"
  }, {
    "product_name" : "Red Hat Quay 3",
    "fix_state" : "Fix deferred",
    "package_name" : "quay/quay-operator-rhel9",
    "cpe" : "cpe:/a:redhat:quay:3"
  }, {
    "product_name" : "Red Hat Quay 3",
    "fix_state" : "Fix deferred",
    "package_name" : "quay/quay-rhel8",
    "cpe" : "cpe:/a:redhat:quay:3"
  }, {
    "product_name" : "Red Hat Quay 3",
    "fix_state" : "Fix deferred",
    "package_name" : "quay/quay-rhel9",
    "cpe" : "cpe:/a:redhat:quay:3"
  }, {
    "product_name" : "Red Hat Trusted Artifact Signer",
    "fix_state" : "Fix deferred",
    "package_name" : "rhtas/certificate-transparency-rhel9",
    "cpe" : "cpe:/a:redhat:trusted_artifact_signer:1"
  }, {
    "product_name" : "Red Hat Trusted Artifact Signer",
    "fix_state" : "Fix deferred",
    "package_name" : "rhtas/cosign-rhel9",
    "cpe" : "cpe:/a:redhat:trusted_artifact_signer:1"
  }, {
    "product_name" : "Red Hat Trusted Artifact Signer",
    "fix_state" : "Fix deferred",
    "package_name" : "rhtas/createtree-rhel9",
    "cpe" : "cpe:/a:redhat:trusted_artifact_signer:1"
  }, {
    "product_name" : "Red Hat Trusted Artifact Signer",
    "fix_state" : "Fix deferred",
    "package_name" : "rhtas/trillian-database-rhel9",
    "cpe" : "cpe:/a:redhat:trusted_artifact_signer:1"
  }, {
    "product_name" : "Red Hat Trusted Artifact Signer",
    "fix_state" : "Fix deferred",
    "package_name" : "rhtas/trillian-logserver-rhel9",
    "cpe" : "cpe:/a:redhat:trusted_artifact_signer:1"
  }, {
    "product_name" : "Red Hat Trusted Artifact Signer",
    "fix_state" : "Fix deferred",
    "package_name" : "rhtas/trillian-logsigner-rhel9",
    "cpe" : "cpe:/a:redhat:trusted_artifact_signer:1"
  }, {
    "product_name" : "Red Hat Trusted Artifact Signer",
    "fix_state" : "Fix deferred",
    "package_name" : "rhtas/updatetree-rhel9",
    "cpe" : "cpe:/a:redhat:trusted_artifact_signer:1"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager",
    "fix_state" : "Fix deferred",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager",
    "fix_state" : "Fix deferred",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager",
    "fix_state" : "Fix deferred",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-server-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:1"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager - Tech Preview",
    "fix_state" : "Fix deferred",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-agent-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager - Tech Preview",
    "fix_state" : "Fix deferred",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-oidc-discovery-provider-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager - Tech Preview",
    "fix_state" : "Fix deferred",
    "package_name" : "zero-trust-workload-identity-manager/spiffe-spire-server-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager - Tech Preview",
    "fix_state" : "Fix deferred",
    "package_name" : "zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-operator-bundle",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
  }, {
    "product_name" : "Zero Trust Workload Identity Manager - Tech Preview",
    "fix_state" : "Fix deferred",
    "package_name" : "zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9",
    "cpe" : "cpe:/a:redhat:zero_trust_workload_identity_manager:0"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-41889\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-41889\nhttps://github.com/jackc/pgx/commit/60644f84918a8af66d14a4b0d865d4edafd955da\nhttps://github.com/jackc/pgx/releases/tag/v5.9.2\nhttps://github.com/jackc/pgx/security/advisories/GHSA-j88v-2chj-qfwx" ],
  "name" : "CVE-2026-41889",
  "mitigation" : {
    "value" : "Avoid using the non-default simple protocol in applications that use the pgx PostgreSQL driver for Go. The vulnerability is contingent on this non-default protocol and specific SQL query constructs. Configuring applications to use the default extended protocol prevents this issue. If the simple protocol is necessary, ensure that dollar-quoted string literals do not contain attacker-controlled placeholder values.",
    "lang" : "en:us"
  },
  "csaw" : false
}