# github.com/lib/pq@v1.12.3 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:09:01.000Z
- Files reviewed: 45
- Findings: 1 medium, 8 low severity findings
- Report: https://security.togoder.click/go/github.com/lib/pq
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/lib/pq@v1.12.3 on Oct 5, 2026. An AI review of 45 source files produced 1 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Insecure TLS configuration

Finding ID: `NPS-B4EA89BB680C`

File: `ssl.go:82`

The code sets InsecureSkipVerify=true for SSLModeRequire and SSLModePrefer, which disables TLS certificate verification and enables man-in-the-middle attacks. This is intentional for libpq compatibility but constitutes a security weakness if used without explicit verify-ca/verify-full modes.

### [low] Test-only fake server

Finding ID: `NPS-D75413B19C62`

File: `internal/pqtest/fake.go`

This package implements a fake PostgreSQL server for testing purposes. It listens only on 127.0.0.1 with an ephemeral port and is intended for use in Go tests. No data exfiltration, credential harvesting, or malicious behavior is present.

### [low] Potential nil pointer dereference / index out of range

Finding ID: `NPS-15B73D321A79`

File: `internal/pqtest/fake.go:107`

ReadStartup parses startup message assuming specific length and splitting without validating msg length >= 6, which could panic on malformed input. This is a robustness issue, not a security concern.

### [low] Incomplete read handling

Finding ID: `NPS-EE6BC1FD4C6C`

File: `internal/pqtest/fake.go:148`

The read() method uses cn.Read() without ensuring the full buffer is filled, which is a correctness bug, not a security issue. However, combined with the error handling for 'connection reset by peer' via string matching, it may mask connection issues. This is not malicious but could cause test flakiness.

### [low] Build-time code generation

Finding ID: `NPS-C2869273CF88`

File: `pqerror/gen.go`

This is a Go code generator guarded by a //go:build ignore tag, so it does not compile into or run as part of the package. It reads local PostgreSQL source files from $HOME/src/postgresql to generate codes.go. No network, credential, shell, or obfuscation behavior is present.

### [low] Out-of-scope file write

Finding ID: `NPS-9D35408705CB`

File: `pqerror/gen.go:133`

The generator writes codes.go with permissions 0o777, which is overly permissive. This is a minor hygiene issue and not malicious in intent, but 0o777 grants world-writable permissions on the generated file.

### [low] Weak TLS renegotiation policy

Finding ID: `NPS-7BBEDB0F196E`

File: `ssl.go:154`

The code unconditionally sets tls.RenegotiateFreelyAsClient, allowing unlimited TLS renegotiation initiated by the server. This can be exploited for DoS and weakens security posture. Comment acknowledges this may be removable but it remains enabled.

### [low] Custom certificate verification bypass

Finding ID: `NPS-A151CFFA7A6F`

File: `ssl.go:166`

verifyCaOnly mode uses client.Handshake() with InsecureSkipVerify=true and then manually verifies only the CA chain via x509.VerifyOptions without setting DNSName on VerifyOptions. This bypasses hostname verification by design (documented as verify-ca semantics), but caller misuse could lead to accepting certs for wrong hosts.

### [low] Sensitive file access

Finding ID: `NPS-5AE2A6B8CF17`

File: `ssl.go:211`

The code reads client certificate/key from ~/.postgresql/postgresql.crt and ~/.postgresql/postgresql.key as libpq does. This is expected behavior for a Postgres driver and not malicious, but it does access user home directory files.

## Files reviewed

- `internal/pqtest/fake.go` (medium): This is a legitimate testing utility for a PostgreSQL driver; no malicious patterns detected, only minor robustness concerns typical of test code.
- `ssl.go` (medium): This is the legitimate lib/pq Postgres driver SSL handling code; no malicious patterns (exfiltration, backdoors, shell exec, obfuscation, install-time hooks) were found, but it intentionally uses InsecureSkipVerify in some SSL modes for libpq compatibility, which is a standard security tradeoff.
- `array.go` (safe): Cleared by Jev triage; no further analysis needed
- `as.go` (safe): Cleared by Jev triage; no further analysis needed
- `as_go126.go` (safe): Cleared by Jev triage; no further analysis needed
- `buf.go` (safe): Cleared by Jev triage; no further analysis needed
- `conn.go` (safe): No malicious patterns detected; this is the legitimate lib/pq PostgreSQL driver connection-handling code.
- `conn_go18.go` (safe): No malicious patterns detected; this is the standard lib/pq Go PostgreSQL driver context implementation with legitimate connection cancellation logic.
- `connector.go` (safe): No malicious patterns detected; this is legitimate PostgreSQL driver connection configuration code with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `copy.go` (safe): No malicious patterns detected; the file implements PostgreSQL COPY IN protocol handling in the lib/pq driver with no exfiltration, credential harvesting, obfuscation, or unauthorized process/network activity.
- `deprecated.go` (safe): Cleared by Jev triage; no further analysis needed
- `doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `encode.go` (safe): Cleared by Jev triage; no further analysis needed
- `error.go` (safe): Cleared by Jev triage; no further analysis needed
- `hstore/hstore.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/pgpass/pgpass.go` (safe): The code is a legitimate implementation of PostgreSQL .pgpass password file parsing with no malicious patterns detected.
- `internal/pgservice/pgservice.go` (safe): No malicious patterns detected; the code is a straightforward parser for PostgreSQL service files.
- `internal/pqsql/copy.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/pqtest/pqtest.go` (safe): No malicious patterns detected; this is a legitimate Go database testing helper package with only test-scoped environment manipulation and standard library usage.
- `internal/pqtest/ztest.go` (safe): No malicious patterns detected; the code contains only standard test helper functions with no exfiltration, obfuscation, or unsafe operations.
- `internal/pqtime/loc.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/pqtime/pqtime.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/pqutil/path.go` (safe): No malicious patterns detected
- `internal/pqutil/perm.go` (safe): No malicious patterns detected
- `internal/pqutil/perm_unsupported.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/pqutil/pqutil.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/pqutil/user_other.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/pqutil/user_posix.go` (safe): No malicious patterns detected
- `internal/pqutil/user_windows.go` (safe): No malicious patterns detected
- `internal/proto/proto.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/proto/sz_32.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/proto/sz_64.go` (safe): Cleared by Jev triage; no further analysis needed
- `krb.go` (safe): The file contains a standard GSSAPI/Kerberos authentication provider registration pattern with no malicious or suspicious code.
- `notice.go` (safe): No malicious patterns detected
- `notify.go` (safe): No malicious patterns detected; the code is a legitimate PostgreSQL LISTEN/NOTIFY implementation with standard connection management and no exfiltration, credential harvesting, or other suspicious behavior.
- `oid/doc.go` (safe): No malicious patterns detected
- `oid/gen.go` (safe): No malicious patterns detected; the file is a build-time code generator for OID constants and contains no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
- `oid/types.go` (safe): No malicious patterns detected
- `pqerror/codes.go` (safe): Cleared by Jev triage; no further analysis needed
- `pqerror/gen.go` (safe): A benign PostgreSQL error-code generator that uses a //go:build ignore tag, reads local source files, and writes generated Go code; no malicious patterns detected.
- `pqerror/pqerror.go` (safe): Cleared by Jev triage; no further analysis needed
- `quote.go` (safe): Cleared by Jev triage; no further analysis needed
- `rows.go` (safe): No malicious patterns detected
- `scram/scram.go` (safe): No malicious patterns detected; the code is a legitimate SCRAM-SHA-256 authentication client implementation.
- `stmt.go` (safe): The code is a standard PostgreSQL driver statement implementation with no malicious patterns detected.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
