Togoder security

Go package security report

github.com/lib/pq@v1.12.3 security report

Risky patterns found that deserve a look.

Needs review Version v1.12.3 Files reviewed 45 Size 292.6 KB Scanned

Summary

Togoder Security scanned the Go package github.com/lib/pq@v1.12.3 on Oct 5, 2026. An AI review of 45 source files produced 1 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
1
medium
8
low

Findings 9

medium

Insecure TLS configuration

NPS-B4EA89BB680C

The code sets InsecureSkipVerify=true for SSLModeRequire and SSLModePrefer, which disables TLS certificate verification and enables man-in-the-middle attacks. This is intentional for libpq compatibility but constitutes a security weakness if used without explicit verify-ca/verify-full modes.

ssl.go:82
low

Test-only fake server

NPS-D75413B19C62

This package implements a fake PostgreSQL server for testing purposes. It listens only on 127.0.0.1 with an ephemeral port and is intended for use in Go tests. No data exfiltration, credential harvesting, or malicious behavior is present.

internal/pqtest/fake.go
low

Potential nil pointer dereference / index out of range

NPS-15B73D321A79

ReadStartup parses startup message assuming specific length and splitting without validating msg length >= 6, which could panic on malformed input. This is a robustness issue, not a security concern.

internal/pqtest/fake.go:107
low

Incomplete read handling

NPS-EE6BC1FD4C6C

The read() method uses cn.Read() without ensuring the full buffer is filled, which is a correctness bug, not a security issue. However, combined with the error handling for 'connection reset by peer' via string matching, it may mask connection issues. This is not malicious but could cause test flakiness.

internal/pqtest/fake.go:148
low

Build-time code generation

NPS-C2869273CF88

This is a Go code generator guarded by a //go:build ignore tag, so it does not compile into or run as part of the package. It reads local PostgreSQL source files from $HOME/src/postgresql to generate codes.go. No network, credential, shell, or obfuscation behavior is present.

pqerror/gen.go
low

Out-of-scope file write

NPS-9D35408705CB

The generator writes codes.go with permissions 0o777, which is overly permissive. This is a minor hygiene issue and not malicious in intent, but 0o777 grants world-writable permissions on the generated file.

pqerror/gen.go:133
low

Weak TLS renegotiation policy

NPS-7BBEDB0F196E

The code unconditionally sets tls.RenegotiateFreelyAsClient, allowing unlimited TLS renegotiation initiated by the server. This can be exploited for DoS and weakens security posture. Comment acknowledges this may be removable but it remains enabled.

ssl.go:154
low

Custom certificate verification bypass

NPS-A151CFFA7A6F

verifyCaOnly mode uses client.Handshake() with InsecureSkipVerify=true and then manually verifies only the CA chain via x509.VerifyOptions without setting DNSName on VerifyOptions. This bypasses hostname verification by design (documented as verify-ca semantics), but caller misuse could lead to accepting certs for wrong hosts.

ssl.go:166
low

Sensitive file access

NPS-5AE2A6B8CF17

The code reads client certificate/key from ~/.postgresql/postgresql.crt and ~/.postgresql/postgresql.key as libpq does. This is expected behavior for a Postgres driver and not malicious, but it does access user home directory files.

ssl.go:211

Files reviewed

FileVerdictWhat the reviewer saw
internal/pqtest/fake.go medium This is a legitimate testing utility for a PostgreSQL driver; no malicious patterns detected, only minor robustness concerns typical of test code.
ssl.go medium This is the legitimate lib/pq Postgres driver SSL handling code; no malicious patterns (exfiltration, backdoors, shell exec, obfuscation, install-time hooks) were found, but it intentionally uses InsecureSkipVerify in some SSL modes for libpq compatibility, which is a standard security tradeoff.
array.go safe Cleared by Jev triage; no further analysis needed
as.go safe Cleared by Jev triage; no further analysis needed
as_go126.go safe Cleared by Jev triage; no further analysis needed
buf.go safe Cleared by Jev triage; no further analysis needed
conn.go safe No malicious patterns detected; this is the legitimate lib/pq PostgreSQL driver connection-handling code.
conn_go18.go safe No malicious patterns detected; this is the standard lib/pq Go PostgreSQL driver context implementation with legitimate connection cancellation logic.
connector.go safe No malicious patterns detected; this is legitimate PostgreSQL driver connection configuration code with no data exfiltration, credential harvesting, obfuscation, or dynamic code execution.
copy.go safe No malicious patterns detected; the file implements PostgreSQL COPY IN protocol handling in the lib/pq driver with no exfiltration, credential harvesting, obfuscation, or unauthorized process/network activity.
deprecated.go safe Cleared by Jev triage; no further analysis needed
doc.go safe Cleared by Jev triage; no further analysis needed
encode.go safe Cleared by Jev triage; no further analysis needed
error.go safe Cleared by Jev triage; no further analysis needed
hstore/hstore.go safe Cleared by Jev triage; no further analysis needed
internal/pgpass/pgpass.go safe The code is a legitimate implementation of PostgreSQL .pgpass password file parsing with no malicious patterns detected.
internal/pgservice/pgservice.go safe No malicious patterns detected; the code is a straightforward parser for PostgreSQL service files.
internal/pqsql/copy.go safe Cleared by Jev triage; no further analysis needed
internal/pqtest/pqtest.go safe No malicious patterns detected; this is a legitimate Go database testing helper package with only test-scoped environment manipulation and standard library usage.
internal/pqtest/ztest.go safe No malicious patterns detected; the code contains only standard test helper functions with no exfiltration, obfuscation, or unsafe operations.
internal/pqtime/loc.go safe Cleared by Jev triage; no further analysis needed
internal/pqtime/pqtime.go safe Cleared by Jev triage; no further analysis needed
internal/pqutil/path.go safe No malicious patterns detected
internal/pqutil/perm.go safe No malicious patterns detected
internal/pqutil/perm_unsupported.go safe Cleared by Jev triage; no further analysis needed
Show 20 more files
FileVerdictWhat the reviewer saw
internal/pqutil/pqutil.go safe Cleared by Jev triage; no further analysis needed
internal/pqutil/user_other.go safe Cleared by Jev triage; no further analysis needed
internal/pqutil/user_posix.go safe No malicious patterns detected
internal/pqutil/user_windows.go safe No malicious patterns detected
internal/proto/proto.go safe Cleared by Jev triage; no further analysis needed
internal/proto/sz_32.go safe Cleared by Jev triage; no further analysis needed
internal/proto/sz_64.go safe Cleared by Jev triage; no further analysis needed
krb.go safe The file contains a standard GSSAPI/Kerberos authentication provider registration pattern with no malicious or suspicious code.
notice.go safe No malicious patterns detected
notify.go safe No malicious patterns detected; the code is a legitimate PostgreSQL LISTEN/NOTIFY implementation with standard connection management and no exfiltration, credential harvesting, or other suspicious behavior.
oid/doc.go safe No malicious patterns detected
oid/gen.go safe No malicious patterns detected; the file is a build-time code generator for OID constants and contains no data exfiltration, credential harvesting, obfuscation, or suspicious network/process activity.
oid/types.go safe No malicious patterns detected
pqerror/codes.go safe Cleared by Jev triage; no further analysis needed
pqerror/gen.go safe A benign PostgreSQL error-code generator that uses a //go:build ignore tag, reads local source files, and writes generated Go code; no malicious patterns detected.
pqerror/pqerror.go safe Cleared by Jev triage; no further analysis needed
quote.go safe Cleared by Jev triage; no further analysis needed
rows.go safe No malicious patterns detected
scram/scram.go safe No malicious patterns detected; the code is a legitimate SCRAM-SHA-256 authentication client implementation.
stmt.go safe The code is a standard PostgreSQL driver statement implementation with no malicious patterns detected.

Frequently asked questions

Is github.com/lib/pq safe to use?

No confirmed malware was found in github.com/lib/pq@v1.12.3, but the review flagged 1 medium, 8 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/lib/pq contain malware?

No malware was identified in github.com/lib/pq@v1.12.3 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/lib/pq checked?

Togoder Security downloaded the published Go package and had an AI model read its 45 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/lib/pq together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/lib/pq@v1.12.3, cost nothing.

Related security reports