CVE-2024-44905: SQL Injection
Published Jun 12, 2025
·Updated
go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/appendvalue.go.
Affected Software
4 affected components
go/github.com/go-pg/pg<=8.0.7
go/github.com/go-pg/pg/v9<=9.2.1
go/github.com/go-pg/pg/v10<=10.13.0
uptrace Pg Go=10.13.0
Event History
Jun 12, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
Affected Software
Advisory Published
via GitHub·06:31 PM
Data Sourced
via GitHub·06:31 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-44905?
CVE-2024-44905 is designated as a critical severity vulnerability due to its potential to allow remote SQL injection attacks.
2
How do I fix CVE-2024-44905?
To fix CVE-2024-44905, upgrade the go-pg library to version 10.13.1 or later.
3
What components are affected by CVE-2024-44905?
CVE-2024-44905 affects the go-pg library specifically in versions up to and including 10.13.0.
4
What type of vulnerability is CVE-2024-44905?
CVE-2024-44905 is a SQL injection vulnerability that can lead to unauthorized data access.
5
Can CVE-2024-44905 impact my application?
Yes, if your application uses the vulnerable versions of the go-pg package, it is at risk of SQL injection exploits.