Package compatibility

node-postgres

Node.js requirements from npm Registry (engines.node) for the pg package. This is not a lifecycle software page.

Compatibility is derived from the declared Node.js version requirement (npm engines.node). CompatHub does not independently test every combination.

Version lines

Each line reflects a declared engines.node tip. Requirement changes across tips appear as separate lines when present.

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

  • CVE-2017-16082GHSA-wc9v-mj63-m9g5

    Remote Code Execution in pg

    Affected:
    <2.11.2; >=3.0.0,<3.6.4; >=4.0.0,<4.5.7; >=5.0.0,<5.2.1; >=6.0.0,<6.0.5; >=6.1.0,<6.1.6; >=6.2.0,<6.2.5; >=6.3.0,<6.3.3; >=6.4.0,<6.4.2; >=7.0.0,<7.0.2; >=7.1.0,<7.1.2
    Fixed in:
    2.11.2, 3.6.4, 4.5.7, 5.2.1, 6.0.5, 6.1.6, 6.2.5, 6.3.3, 6.4.2, 7.0.2, 7.1.2
    Source:
    OSV source · Advisory