Description
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Published: 2026-10-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

To mitigate this issue, restrict network access to the `postgres-exporter` service. Implement a Kubernetes `NetworkPolicy` to limit inbound connections to the `postgres-exporter` service's metrics port (9187) to only the Prometheus scraper or other trusted monitoring components within the cluster. This prevents unauthorized access to the exposed debug endpoints. Consult the OpenShift documentation for creating and applying `NetworkPolicy` resources.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Postgres-exporter
Postgres-exporter postgres-exporter
Vendors & Products Postgres-exporter
Postgres-exporter postgres-exporter

Wed, 07 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Title Postgres-exporter: net/http/pprof exposed on metrics listener
First Time appeared Redhat
Redhat multicluster Globalhub
Weaknesses CWE-489
CPEs cpe:/a:redhat:multicluster_globalhub
Vendors & Products Redhat
Redhat multicluster Globalhub
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Postgres-exporter Postgres-exporter
Redhat Multicluster Globalhub
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-06T18:11:35.414Z

Reserved: 2026-08-31T18:17:41.963Z

Link: CVE-2026-83550

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:16.280

Modified: 2026-10-06T20:05:39.400

Link: CVE-2026-83550

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-06T16:00:00Z

Links: CVE-2026-83550 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T06:00:08Z

Weaknesses