CVE-2026-83550
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Summary
A flaw was found in postgres-exporter. Due to the blank import of net/http/pprof, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-489: Active Debug Code
Workarounds
To mitigate this issue, restrict network access to the postgres-exporter service. Implement a Kubernetes NetworkPolicy to limit inbound connections to the postgres-exporter service's metrics port (9187) to only the Prometheus scraper or other trusted monitoring components within the cluster. This prevents unauthorized access to the exposed debug endpoints. Consult the OpenShift documentation for creating and applying NetworkPolicy resources.
References
- https://access.redhat.com/security/cve/CVE-2026-83550
- https://bugzilla.redhat.com/show_bug.cgi?id=2526444
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.