CVE-2026-83550
Beschrijving NL
Er werd een fout gevonden in de postgres-exporteur. Vanwege de lege import van `net/http/pprof` worden debug-eindpunten weergegeven op de niet-geverifieerde metrics-listener. Een externe aanvaller binnen het clusternetwerk heeft toegang tot deze eindpunten. Dit zorgt voor openbaarmaking van informatie, mogelijk onthullende procesargumenten, volledige goroutine-stacks en gevoelige gegevens zoals databaseverbindingsreeksen of wachtwoorden van heap dumps. Bovendien kan herhaalde CPU-profilering via deze eindpunten leiden tot een denial of service.
Origineel (Engels) tonen
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.