Intel

AIKIDO-2025-10069

postgres-types is vulnerable to Uncaught Exception

Uncaught Exception Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

18

Low Risk

This Affects:

RUSTpostgres-types
0.1.0 - 0.2.8
Fixed in 0.2.9

TL;DR

Affected versions of this package are vulnerable to uncaught exceptions. A panic occurs when attempting to retrieve a PrimitiveDateTime value in the from_sql function, if it is set to infinity. This issue can cause unexpected crashes, potential denial-of-service (DoS) conditions, or instability in applications relying on this functionality.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

postgres-types is vulnerable to Uncaught Exception in versions 0.1.0 - 0.2.8.

How to fix this

Upgrade the postgres-types library to the patch version.