Summary
Togoder Security scanned the Go package github.com/lib/pq@v1.12.3 on Oct 5, 2026. An AI review of 45 source files produced 1 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.
Findings 9
Insecure TLS configuration
NPS-B4EA89BB680C
The code sets InsecureSkipVerify=true for SSLModeRequire and SSLModePrefer, which disables TLS certificate verification and enables man-in-the-middle attacks. This is intentional for libpq compatibility but constitutes a security weakness if used without explicit verify-ca/verify-full modes.
Test-only fake server
NPS-D75413B19C62
This package implements a fake PostgreSQL server for testing purposes. It listens only on 127.0.0.1 with an ephemeral port and is intended for use in Go tests. No data exfiltration, credential harvesting, or malicious behavior is present.
Potential nil pointer dereference / index out of range
NPS-15B73D321A79
ReadStartup parses startup message assuming specific length and splitting without validating msg length >= 6, which could panic on malformed input. This is a robustness issue, not a security concern.
Incomplete read handling
NPS-EE6BC1FD4C6C
The read() method uses cn.Read() without ensuring the full buffer is filled, which is a correctness bug, not a security issue. However, combined with the error handling for 'connection reset by peer' via string matching, it may mask connection issues. This is not malicious but could cause test flakiness.
Build-time code generation
NPS-C2869273CF88
This is a Go code generator guarded by a //go:build ignore tag, so it does not compile into or run as part of the package. It reads local PostgreSQL source files from $HOME/src/postgresql to generate codes.go. No network, credential, shell, or obfuscation behavior is present.
Out-of-scope file write
NPS-9D35408705CB
The generator writes codes.go with permissions 0o777, which is overly permissive. This is a minor hygiene issue and not malicious in intent, but 0o777 grants world-writable permissions on the generated file.
Weak TLS renegotiation policy
NPS-7BBEDB0F196E
The code unconditionally sets tls.RenegotiateFreelyAsClient, allowing unlimited TLS renegotiation initiated by the server. This can be exploited for DoS and weakens security posture. Comment acknowledges this may be removable but it remains enabled.
Custom certificate verification bypass
NPS-A151CFFA7A6F
verifyCaOnly mode uses client.Handshake() with InsecureSkipVerify=true and then manually verifies only the CA chain via x509.VerifyOptions without setting DNSName on VerifyOptions. This bypasses hostname verification by design (documented as verify-ca semantics), but caller misuse could lead to accepting certs for wrong hosts.
Sensitive file access
NPS-5AE2A6B8CF17
The code reads client certificate/key from ~/.postgresql/postgresql.crt and ~/.postgresql/postgresql.key as libpq does. This is expected behavior for a Postgres driver and not malicious, but it does access user home directory files.
Files reviewed
| File | Verdict | What the reviewer saw |
|---|---|---|
| internal/pqtest/fake.go | medium | This is a legitimate testing utility for a PostgreSQL driver; no malicious patterns detected, only minor robustness concerns typical of test code. |
| ssl.go | medium | This is the legitimate lib/pq Postgres driver SSL handling code; no malicious patterns (exfiltration, backdoors, shell exec, obfuscation, install-time hooks) were found, but it intentionally uses InsecureSkipVerify in some SSL modes for libpq compatibility, which is a standard security tradeoff. |
| array.go | safe | Cleared by Jev triage; no further analysis needed |
| as.go | safe | Cleared by Jev triage; no further analysis needed |
| as_go126.go | safe | Cleared by Jev triage; no further analysis needed |
| buf.go | safe | Cleared by Jev triage; no further analysis needed |
| conn.go | safe | No malicious patterns detected; this is the legitimate lib/pq PostgreSQL driver connection-handling code. |
| conn_go18.go | safe | No malicious patterns detected; this is the standard lib/pq Go PostgreSQL driver context implementation with legitimate connection cancellation logic. |
| connector.go | safe | No malicious patterns detected; this is legitimate PostgreSQL driver connection configuration code with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution. |
| copy.go | safe | No malicious patterns detected; the file implements PostgreSQL COPY IN protocol handling in the lib/pq driver with no exfiltration, credential harvesting, obfuscation, or unauthorized process/network activity. |
| deprecated.go | safe | Cleared by Jev triage; no further analysis needed |
| doc.go | safe | Cleared by Jev triage; no further analysis needed |
| encode.go | safe | Cleared by Jev triage; no further analysis needed |
| error.go | safe | Cleared by Jev triage; no further analysis needed |
| hstore/hstore.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/pgpass/pgpass.go | safe | The code is a legitimate implementation of PostgreSQL .pgpass password file parsing with no malicious patterns detected. |
| internal/pgservice/pgservice.go | safe | No malicious patterns detected; the code is a straightforward parser for PostgreSQL service files. |
| internal/pqsql/copy.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/pqtest/pqtest.go | safe | No malicious patterns detected; this is a legitimate Go database testing helper package with only test-scoped environment manipulation and standard library usage. |
| internal/pqtest/ztest.go | safe | No malicious patterns detected; the code contains only standard test helper functions with no exfiltration, obfuscation, or unsafe operations. |
| internal/pqtime/loc.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/pqtime/pqtime.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/pqutil/path.go | safe | No malicious patterns detected |
| internal/pqutil/perm.go | safe | No malicious patterns detected |
| internal/pqutil/perm_unsupported.go | safe | Cleared by Jev triage; no further analysis needed |
Show 20 more files
| File | Verdict | What the reviewer saw |
|---|---|---|
| internal/pqutil/pqutil.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/pqutil/user_other.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/pqutil/user_posix.go | safe | No malicious patterns detected |
| internal/pqutil/user_windows.go | safe | No malicious patterns detected |
| internal/proto/proto.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/proto/sz_32.go | safe | Cleared by Jev triage; no further analysis needed |
| internal/proto/sz_64.go | safe | Cleared by Jev triage; no further analysis needed |
| krb.go | safe | The file contains a standard GSSAPI/Kerberos authentication provider registration pattern with no malicious or suspicious code. |
| notice.go | safe | No malicious patterns detected |
| notify.go | safe | No malicious patterns detected; the code is a legitimate PostgreSQL LISTEN/NOTIFY implementation with standard connection management and no exfiltration, credential harvesting, or other suspicious behavior. |
| oid/doc.go | safe | No malicious patterns detected |
| oid/gen.go | safe | No malicious patterns detected; the file is a build-time code generator for OID constants and contains no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity. |
| oid/types.go | safe | No malicious patterns detected |
| pqerror/codes.go | safe | Cleared by Jev triage; no further analysis needed |
| pqerror/gen.go | safe | A benign PostgreSQL error-code generator that uses a //go:build ignore tag, reads local source files, and writes generated Go code; no malicious patterns detected. |
| pqerror/pqerror.go | safe | Cleared by Jev triage; no further analysis needed |
| quote.go | safe | Cleared by Jev triage; no further analysis needed |
| rows.go | safe | No malicious patterns detected |
| scram/scram.go | safe | No malicious patterns detected; the code is a legitimate SCRAM-SHA-256 authentication client implementation. |
| stmt.go | safe | The code is a standard PostgreSQL driver statement implementation with no malicious patterns detected. |
Frequently asked questions
Is github.com/lib/pq safe to use?
No confirmed malware was found in github.com/lib/pq@v1.12.3, but the review flagged 1 medium, 8 low severity findings for risky patterns worth checking before you rely on it.
Does github.com/lib/pq contain malware?
No malware was identified in github.com/lib/pq@v1.12.3 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.
How was github.com/lib/pq checked?
Togoder Security downloaded the published Go package and had an AI model read its 45 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.
How do I scan github.com/lib/pq together with the rest of my dependencies?
Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/lib/pq@v1.12.3, cost nothing.