Exploitation Summary
EIP tracks 1 public exploit for CVE-2026-32286. PoCs published by moisei-dev.
AI-analyzed exploit summary This repository appears to be a legitimate Go-based database migration tool, but it does not contain any exploit code or proof-of-concept for CVE-2026-32286. The files are related to a migration helper library with various database drivers.
Description
The DataRow.Decode function fails to properly validate field lengths. A malicious or compromised PostgreSQL server can send a DataRow message with a negative field length, causing a slice bounds out of range panic.
Exploits (1)
This repository appears to be a legitimate Go-based database migration tool, but it does not contain any exploit code or proof-of-concept for CVE-2026-32286. The files are related to a migration helper library with various database drivers.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H