Medium severity6.5NVD Advisory· Published Jun 12, 2025· Updated Jun 17, 2026
CVE-2024-44905
CVE-2024-44905
Description
go-pg pg v10.13.0 was discovered to contain a SQL injection vulnerability via the component /types/append_value.go.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/go-pg/pg/v10Go | < 10.15.0 | 10.15.0 |
github.com/go-pg/pg/v9Go | <= 9.2.1 | — |
github.com/go-pg/pgGo | <= 8.0.7 | — |
Affected products
10- go-pg/pgdescription
- ghsa-coords8 versionspkg:golang/github.com/go-pg/pg/v10pkg:golang/github.com/go-pg/pg/v9pkg:golang/github.com/go-pg/pgpkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweedpkg:apk/wolfi/nucleipkg:apk/chainguard/nucleipkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6
< 10.15.0+ 7 more
- (no CPE)range: < 10.15.0
- (no CPE)range: <= 9.2.1
- (no CPE)range: <= 8.0.7
- (no CPE)range: < 0.0.20250730T213748-1.1
- (no CPE)range: < 3.5.1-r0
- (no CPE)range: < 3.5.1-r0
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
- (no CPE)range: < 0.0.20251230T014957-150000.1.134.1
Patches
Vulnerability mechanics
References
8- media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Paul%20Gerste%20-%20SQL%20Injection%20Isn%27t%20Dead%20Smuggling%20Queries%20at%20the%20Protocol%20Level.pdfnvdExploitWEB
- www.sonarsource.com/blog/double-dash-double-trouble-a-subtle-sql-injection-flaw/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-6xp3-p59p-q4fjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-44905ghsaADVISORY
- github.com/go-pg/pg/blob/30e7053c6cacdd44d06cf2b92183b49188b7c922/types/append_value.gonvdProductWEB
- github.com/go-pg/pg/commit/eff50a43724e52347559687a6945c116afbb41c1ghsaWEB
- github.com/go-pg/pg/releases/tag/v10.15.0ghsaWEB
- www.sonarsource.com/blog/double-dash-double-trouble-a-subtle-sql-injection-flawghsaWEB
News mentions
0No linked articles in our index yet.