Description
asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.
Scores
CVSS v3
9.8
EPSS
0.0214
EPSS Percentile
84.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-824
Status
published
Products (3)
debian/debian_linux
9.0
magic/asyncpg
< 0.21.0
pypi/asyncpg
0 - 0.21.0PyPI
Published
Aug 12, 2020
Tracked Since
Feb 18, 2026