A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

To mitigate this issue, restrict network access to the `postgres-exporter` service. Implement a Kubernetes `NetworkPolicy` to limit inbound connections to the `postgres-exporter` service's metrics port (9187) to only the Prometheus scraper or other trusted monitoring components within the cluster. This prevents unauthorized access to the exposed debug endpoints. Consult the OpenShift documentation for creating and applying `NetworkPolicy` resources.

History

Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Title Postgres-exporter: net/http/pprof exposed on metrics listener
First Time appeared Redhat
Redhat multicluster Globalhub
Weaknesses CWE-489
CPEs cpe:/a:redhat:multicluster_globalhub
Vendors & Products Redhat
Redhat multicluster Globalhub
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-06T18:11:35.414Z

Reserved: 2026-08-31T18:17:41.963Z

Link: CVE-2026-83550

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T19:18:16.280

Modified: 2026-10-06T19:18:16.280

Link: CVE-2026-83550

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses