Description
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Published: 2026-10-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

To mitigate this issue, restrict network access to the `postgres-exporter` service. Implement a Kubernetes `NetworkPolicy` to limit inbound connections to the `postgres-exporter` service's metrics port (9187) to only the Prometheus scraper or other trusted monitoring components within the cluster. This prevents unauthorized access to the exposed debug endpoints. Consult the OpenShift documentation for creating and applying `NetworkPolicy` resources.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Title Postgres-exporter: net/http/pprof exposed on metrics listener
First Time appeared Redhat
Redhat multicluster Globalhub
Weaknesses CWE-489
CPEs cpe:/a:redhat:multicluster_globalhub
Vendors & Products Redhat
Redhat multicluster Globalhub
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Redhat Multicluster Globalhub
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-06T18:11:35.414Z

Reserved: 2026-08-31T18:17:41.963Z

Link: CVE-2026-83550

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses