{"api_version":"1","generated_at":"2026-10-10T00:38:39+00:00","cve":"CVE-2026-83550","urls":{"html":"https://cve.report/CVE-2026-83550","api":"https://cve.report/api/cve/CVE-2026-83550.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-83550","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-83550"},"summary":{"title":"Postgres-exporter: net/http/pprof exposed on metrics listener","description":"A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-10-06 19:18:16","updated_at":"2026-10-07 21:17:20"},"problem_types":["CWE-489","CWE-489 Active Debug Code"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Secondary","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"7.1","severity":"HIGH","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2526444","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2526444","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-83550","name":"https://access.redhat.com/security/cve/CVE-2026-83550","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-83550","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-83550","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Multicluster Global Hub","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-08-31T00:00:00.000Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-10-06T16:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[{"source":"CNA","title":"","value":"To mitigate this issue, restrict network access to the `postgres-exporter` service. Implement a Kubernetes `NetworkPolicy` to limit inbound connections to the `postgres-exporter` service's metrics port (9187) to only the Prometheus scraper or other trusted monitoring components within the cluster. This prevents unauthorized access to the exposed debug endpoints. Consult the OpenShift documentation for creating and applying `NetworkPolicy` resources.","time":"","lang":"en"}],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"83550","cve":"CVE-2026-83550","epss":"0.002080000","percentile":"0.099810000","score_date":"2026-10-07","updated_at":"2026-10-08 00:05:43"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-83550","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-07T20:03:10.342549Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-10-07T20:04:07.587Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:multicluster_globalhub"],"defaultStatus":"affected","packageName":"multicluster-globalhub/multicluster-globalhub-postgres-exporter-rhel9","product":"Multicluster Global Hub","vendor":"Red Hat"}],"datePublic":"2026-10-06T16:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"ADJACENT_NETWORK","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-489","description":"Active Debug Code","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-06T18:11:35.414Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-83550"},{"name":"RHBZ#2526444","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2526444"}],"timeline":[{"lang":"en","time":"2026-08-31T00:00:00.000Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-10-06T16:00:00.000Z","value":"Made public."}],"title":"Postgres-exporter: net/http/pprof exposed on metrics listener","workarounds":[{"lang":"en","value":"To mitigate this issue, restrict network access to the `postgres-exporter` service. Implement a Kubernetes `NetworkPolicy` to limit inbound connections to the `postgres-exporter` service's metrics port (9187) to only the Prometheus scraper or other trusted monitoring components within the cluster. This prevents unauthorized access to the exposed debug endpoints. Consult the OpenShift documentation for creating and applying `NetworkPolicy` resources."}],"x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-489: Active Debug Code"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-83550","datePublished":"2026-10-06T18:11:35.414Z","dateReserved":"2026-08-31T18:17:41.963Z","dateUpdated":"2026-10-07T20:04:07.587Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-06 19:18:16","lastModifiedDate":"2026-10-07 21:17:20","problem_types":["CWE-489","CWE-489 Active Debug Code"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":4.2}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-07T20:03:10.342549Z","id":"CVE-2026-83550","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"83550","Ordinal":"1","Title":"Postgres-exporter: net/http/pprof exposed on metrics listener","CVE":"CVE-2026-83550","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"83550","Ordinal":"1","NoteData":"A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.","Type":"Description","Title":"Postgres-exporter: net/http/pprof exposed on metrics listener"}]}}}