High severity7.5NVD Advisory· Published Jan 5, 2023· Updated Jun 17, 2026
CVE-2023-22626
CVE-2023-22626
Description
PgHero before 3.1.0 allows Information Disclosure via EXPLAIN because query results may be present in an error message. (Depending on database user privileges, this may only be information from the database, or may be information from file contents on the database server.)
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pgheroRubyGems | < 3.1.0 | 3.1.0 |
Affected products
3- PgHero/PgHerodescription
Patches
Vulnerability mechanics
References
4- github.com/ankane/pghero/issues/439nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-vf99-xw26-86g5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-22626ghsaADVISORY
- github.com/rubysec/ruby-advisory-db/blob/master/gems/pghero/CVE-2023-22626.ymlghsaWEB
News mentions
0No linked articles in our index yet.