Package compatibility
node-postgres
Node.js requirements from npm Registry (engines.node) for the pg package. This is not a lifecycle software page.
Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.
Version lines
Each line reflects a declared engines.node tip. Requirement changes across tips appear as separate lines when present.
Known vulnerabilities
Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.
- CVE-2017-16082GHSA-wc9v-mj63-m9g5
Remote Code Execution in pg
- Affected:
- <2.11.2; >=3.0.0,<3.6.4; >=4.0.0,<4.5.7; >=5.0.0,<5.2.1; >=6.0.0,<6.0.5; >=6.1.0,<6.1.6; >=6.2.0,<6.2.5; >=6.3.0,<6.3.3; >=6.4.0,<6.4.2; >=7.0.0,<7.0.2; >=7.1.0,<7.1.2
- Fixed in:
- 2.11.2, 3.6.4, 4.5.7, 5.2.1, 6.0.5, 6.1.6, 6.2.5, 6.3.3, 6.4.2, 7.0.2, 7.1.2
- Source:
- OSV source · Advisory
