MinorCritical vulnerability
CVE-2026-83550 (CVSS 7.1)
NVD · officialPublished Oct 6, 2026Risk 23/100
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Technical details
CVSS
7.1
AV:Adjacent NetworkAC:LowPR:NoneUI:NoneC:LowI:NoneA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source