{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-83550", "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "state": "PUBLISHED", "assignerShortName": "redhat", "dateReserved": "2026-08-31T18:17:41.963Z", "datePublished": "2026-10-06T18:11:35.414Z", "dateUpdated": "2026-10-07T20:04:07.587Z" }, "containers": { "cna": { "title": "Postgres-exporter: net/http/pprof exposed on metrics listener", "metrics": [ { "other": { "content": { "value": "Moderate", "namespace": "https://access.redhat.com/security/updates/classification/" }, "type": "Red Hat severity rating" } }, { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "HIGH", "baseScore": 7.1, "baseSeverity": "HIGH", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "version": "3.1" }, "format": "CVSS" } ], "descriptions": [ { "lang": "en", "value": "A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service." } ], "affected": [ { "vendor": "Red Hat", "product": "Multicluster Global Hub", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9", "defaultStatus": "affected", "cpes": [ "cpe:/a:redhat:multicluster_globalhub" ] } ], "references": [ { "url": "https://access.redhat.com/security/cve/CVE-2026-83550", "tags": [ "vdb-entry", "x_refsource_REDHAT" ] }, { "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2526444", "name": "RHBZ#2526444", "tags": [ "issue-tracking", "x_refsource_REDHAT" ] } ], "datePublic": "2026-10-06T16:00:00.000Z", "problemTypes": [ { "descriptions": [ { "cweId": "CWE-489", "description": "Active Debug Code", "lang": "en", "type": "CWE" } ] } ], "x_redhatCweChain": "CWE-489: Active Debug Code", "workarounds": [ { "lang": "en", "value": "To mitigate this issue, restrict network access to the `postgres-exporter` service. Implement a Kubernetes `NetworkPolicy` to limit inbound connections to the `postgres-exporter` service's metrics port (9187) to only the Prometheus scraper or other trusted monitoring components within the cluster. This prevents unauthorized access to the exposed debug endpoints. Consult the OpenShift documentation for creating and applying `NetworkPolicy` resources." } ], "timeline": [ { "lang": "en", "time": "2026-08-31T00:00:00.000Z", "value": "Reported to Red Hat." }, { "lang": "en", "time": "2026-10-06T16:00:00.000Z", "value": "Made public." } ], "providerMetadata": { "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat", "dateUpdated": "2026-10-06T18:11:35.414Z" }, "x_generator": { "engine": "cvelib 1.8.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-07T20:03:10.342549Z", "id": "CVE-2026-83550", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-07T20:04:07.587Z" } } ] } }