libinjection-go is vulnerable to Protection Mechanism Failure
40
Medium Risk
Affected versions of libinjection-go contain an issue in the SQL injection detection logic inherited from the upstream libinjection library. Due to incorrect token parsing in the SQL tokenizer, specially crafted input strings may not be correctly identified as SQL injection attempts. An attacker could exploit this behavior to bypass SQL injection detection mechanisms in applications or web application firewalls that rely on this library, potentially allowing malicious SQL payloads to reach backend systems. The issue is addressed by updating the parser logic to correctly recognize previously undetected injection patterns.
You are affected if you are using a version that falls within the vulnerable range.
libinjection-go is vulnerable to Protection Mechanism Failure in versions 0.1.0 - 0.2.3.
Upgrade the libinjection-go library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant