CVE-2024-27304 is a SQL injection vulnerability in pgx, a PostgreSQL driver and toolkit for Go. The flaw occurs when an attacker can cause a single PostgreSQL query or bind protocol message to exceed 4 GB in size. In that condition, an integer overflow in the driver's calculated message size can cause what should be one large message to be emitted as multiple protocol messages under attacker control. This breaks the intended framing of the PostgreSQL wire protocol and can allow attacker-influenced SQL to be interpreted separately, resulting in SQL injection. Fixed releases are pgx v4.18.2 and v5.5.4.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains both a vulnerable demo web application and two Python exploit implementations targeting the same underlying idea: abuse of PostgreSQL pgx-backed request handling by sending a massive streamed login field that embeds PostgreSQL wire-protocol messages and SQL statements. The Go application (main.go, handlers.go) is a small insurance dashboard with login, dashboard, and logout routes, PostgreSQL-backed users/sessions tables, HTML templates, and SQL setup scripts. The login flow is notable because it decodes attacker-supplied username data to a temporary file and then uses the decoded content in authentication logic, creating the attack surface exercised by the exploit scripts. Repository structure: main.go initializes the HTTP server and PostgreSQL pool from DATABASE_URL and PORT. handlers.go implements session management, CSRF handling, login/dashboard/logout handlers, and the base64 username decoding helper that writes to an OS temp subdirectory. SQL setup files create users and sessions tables, seed an admin account, and remove expired sessions. templates/ contains the login and dashboard UI. The insurance_demo_exploit/ directory contains the main exploit driver and a payload generator that streams a 2^32-byte payload as base64 inside the username form field to /login. The payload includes PostgreSQL protocol frames for SYNC, ROLLBACK, INSERT, and COMMIT, ultimately inserting a new demo user into the users table. The harbor_exploit/ directory adapts the same technique to Harbor’s /c/login endpoint, harvesting Harbor CSRF/session state and streaming a URL-encoded principal field that inserts a new sysadmin account into harbor_user. Main exploit capabilities: create unauthorized accounts directly in the backend database, including admin/sysadmin access; evade memory limits by streaming payloads in chunks; support small alignment offsets (0-4 bytes) to tune the NOP/padding placement; and target either the included demo app or Harbor. This is an actual exploit repository rather than a detector. It is operational because it contains working payload generation and delivery logic, but payloads and targets are largely hardcoded rather than fully generalized.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-27304, a protocol-level SQL injection vulnerability in the pgx PostgreSQL driver (v5.5.3) when used in Simple Protocol mode. The repository contains a vulnerable web application (written in Go) that uses pgx to connect to a PostgreSQL database and exposes a /login endpoint. The exploit scripts (in Python) craft and send large, specially constructed HTTP POST requests to the /login endpoint, exploiting the way pgx handles PostgreSQL protocol messages to inject arbitrary SQL or cause a denial of service. The exploit requires knowledge of the query structure and is most effective when the application uses the Simple Protocol mode. The repository is structured with a 'webapp' directory containing the vulnerable application and a set of 'exploit' scripts demonstrating different attack techniques. The main attack vector is network-based, targeting the HTTP interface of the web application.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.