CVE-2026-83550 — Red Hat
HIGHCVE-2026-83550 is a high-severity (CVSS 7.1) CWE-489 vulnerability. No vendor fix is recorded yet; mitigation options are listed below.
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the…
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2026-83550 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 383,485 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Description
A flaw was found in postgres-exporter. Due to the blank import of net/http/pprof, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Detection & mitigation playbook
VulnerabilityDetect
Identify every host running the affected component and compare the installed build against the fixed version below — for source-built or distro-packaged software the version string, not a lockfile, is the source of truth (`dpkg -l`, `rpm -q`, or the binary's own `--version`).
Remediation status
No fixed release is recorded for CVE-2026-83550 yet. Track the upstream advisory, and apply the exposure-reduction steps below in the meantime.
Mitigate without a patch
Assume what was exposed is already known: rotate any credential, token or key that the affected component could return, restrict the endpoint to callers that genuinely need it, and strip sensitive fields from responses and error output at the boundary rather than relying on the client not to read them.
Fixing This On Your OS
If you run this on a Linux distribution, patch through your package manager against the distro's own security advisory below — it tracks the exact backported fix for your release, which can ship on a different timeline (and sometimes a different severity) than the upstream project.
This vulnerability is rated as Moderate severity because exposure is confined to internal cluster network traffic and does not allow direct remote code execution or data modification. In default Multicluster Global Hub environments, the postgres-exporter service exposes profiling interfaces alongside metrics endpoints…
To mitigate this issue, restrict network access to the `postgres-exporter` service. Implement a Kubernetes `NetworkPolicy` to limit inbound connections to the `postgres-exporter` service's metrics port (9187) to only the Prometheus scraper or other trusted monitoring components within the cluster. This prevents unauthorized access to the exposed debug endpoints. Consult the OpenShift documentation for creating and applying `NetworkPolicy` resources.Source: Red Hat security advisory for CVE-2026-83550 (CC BY 4.0)
Frequently Asked Questions
Is CVE-2026-83550 in your dependencies?
Find it across , including transitive dependencies.