OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-83550 (CVSS 7.1)

NVD · officialPublished Oct 6, 2026Risk 23/100

A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.

CVSS
7.1
AV:Adjacent NetworkAC:LowPR:NoneUI:NoneC:LowI:NoneA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source