CVE-2026-41889: pgx: SQL Injection via placeholder confusion with dollar quoted string literals

Overview

Severity
N/A
Exploit Status
Not Exploited
Patch Tuesday
2026-May
Released
2026-05-10
Last Updated
2026-06-03
EPSS Score
0.36% (percentile: 27.3%)

Affected Products (4)

Other

  • 21007-17084
  • 21412-17084
  • 21395-17084

Open Source Software

  • azl3 telegraf 1.31.0-19 on Azure Linux 3.0

Revision History

  • 2026-05-10: Information published.
  • 2026-05-11: Information published.
  • 2026-06-03: Information published.