Description
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Published: 2026-10-06
Score: 7.1 High
EPSS: n/a
KEV: No
Impact: Information Disclosure, Denial of Service
Action: Restrict Network
AI Analysis

Impact

A flaw in postgres-exporter causes the net/http/pprof package to be imported, adding unprotected debug endpoints to the metrics listener. The exposed pprof endpoints allow an attacker inside the cluster network to obtain sensitive information such as process arguments, goroutine stacks, and database connection strings, and repeated profiling requests can exhaust CPU resources, leading to a denial of service. The weakness is rooted in CWE‑489, exposing internal application details that should be protected.

Affected Systems

Red Hat Multicluster Global Hub is the identified product affected by this issue. The specific versions impacted were not disclosed in the advisory.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.1, indicating high severity. EPSS data is not available, but the attack requires only intra‑cluster network access, making exploitation likely for anyone who can reach the metrics port 9187. The issue is not listed in the CISA KEV catalog, so no known widespread exploitation has been reported yet. Given the potential for both information disclosure and service disruption, the risk remains significant for any cluster that permits unrestricted metric port traffic.

Generated by OpenCVE AI on October 6, 2026 at 20:01 UTC.

Remediation

Vendor Workaround

To mitigate this issue, restrict network access to the `postgres-exporter` service. Implement a Kubernetes `NetworkPolicy` to limit inbound connections to the `postgres-exporter` service's metrics port (9187) to only the Prometheus scraper or other trusted monitoring components within the cluster. This prevents unauthorized access to the exposed debug endpoints. Consult the OpenShift documentation for creating and applying `NetworkPolicy` resources.


OpenCVE Recommended Actions

  • Implement a Kubernetes NetworkPolicy that limits inbound connections to the postgres-exporter metrics port (9187) to only the Prometheus scraper, and restrict access to the debug endpoints by configuring or modifying postgres-exporter so that it does not import net/http/pprof, if the code base allows this change.
  • Stay alert for and apply any official patch or update from Red Hat that resolves this issue as soon as it becomes available.
  • Confirm that no other pod or service can reach port 9187 by reviewing cluster network policies and audit logs, ensuring that the metrics listener is isolated from unauthorized traffic.

Generated by OpenCVE AI on October 6, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 06 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Title Postgres-exporter: net/http/pprof exposed on metrics listener
First Time appeared Redhat
Redhat multicluster Globalhub
Weaknesses CWE-489
CPEs cpe:/a:redhat:multicluster_globalhub
Vendors & Products Redhat
Redhat multicluster Globalhub
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


Subscriptions

Redhat Multicluster Globalhub
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-06T18:11:35.414Z

Reserved: 2026-08-31T18:17:41.963Z

Link: CVE-2026-83550

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:16.280

Modified: 2026-10-06T20:05:39.400

Link: CVE-2026-83550

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-06T16:00:00Z

Links: CVE-2026-83550 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T20:15:05Z

Weaknesses