{"id":"GHSA-5x78-73v4-xg6w","aliases":["RUSTSEC-2026-0179"],"url":"https://o3.security/vulnerability/GHSA-5x78-73v4-xg6w","summary":"postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service","details":"A malicious, compromised, or man-in-the-middle server can supply an arbitrarily\nlarge SCRAM-SHA-256 PBKDF2 iteration count during authentication. The client\nruns it inline with no upper bound, pinning a `tokio` worker thread for minutes\nper connection, possibly stalling the whole async runtime.\n\nApplications that connect only to a trusted database are not exposed; the risk\napplies to clients that may connect to untrusted or user-supplied servers, or\nwhose connection can be intercepted by a man-in-the-middle.","published":"2026-08-24T19:43:31Z","modified":"2026-08-25T02:55:59.697476289Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"postgres-protocol","fixedVersion":"0.6.12"}],"fix":{"url":"https://github.com/rust-postgres/rust-postgres/commit/d40097a36a85068ea50a3afbf0ce154ba439e7f0","label":"rust-postgres/rust-postgres@d40097a"},"references":[{"type":"WEB","url":"https://github.com/rust-postgres/rust-postgres/commit/d40097a36a85068ea50a3afbf0ce154ba439e7f0"},{"type":"PACKAGE","url":"https://github.com/rust-postgres/rust-postgres"},{"type":"WEB","url":"https://github.com/rust-postgres/rust-postgres/releases/tag/postgres-protocol-v0.6.12"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0179.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-25T02:55:59.697476289Z"}}