{"id":"CVE-2026-54711","aliases":["PYSEC-2026-2872"],"url":"https://o3.security/vulnerability/CVE-2026-54711","summary":"PGHoard: Password written to debug log","details":"### Impact\nWhen using .pgpass, database connection information including the username and password will be logged at the debug level.\n\n### Patches\nUpgrade to version 2.7.1 or greater.\n\n### Workarounds\nFilter out debug-level logs.\n\n### References\nThis issue was discovered by BugCrowd user DRAKOKORIAN.","published":"2026-06-18T15:05:20Z","modified":"2026-07-13T16:42:55.738011130Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"PyPI","name":"pghoard","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Aiven-Open/pghoard/security/advisories/GHSA-mpx4-jmpr-vm8v"},{"type":"PACKAGE","url":"https://github.com/Aiven-Open/pghoard"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-13T16:42:55.738011130Z"}}