Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-83550

HIGH NVD
CVSS Score 7.1
Severity HIGH
Published Oct 06, 2026
Vendor unknown

Description

A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.

References