Skip to content
Threat Feed
high advisory

Information Disclosure via Exposed net/http/pprof in postgres-exporter

An unauthenticated exposure of Go pprof debug endpoints in postgres-exporter allows remote attackers to perform information disclosure of credentials and process memory or trigger a denial of service.

CVE search metadata

CVE search record: CVE-2026-83550. Severity: high. CVSS: 7.1. KEV: no. Product: postgres-exporter. Brief: Information Disclosure via Exposed net/http/pprof in postgres-exporter. Brief link: https://feed.craftedsignal.io/briefs/2026-10-postgres-exporter-pprof/

The postgres-exporter software contains a vulnerability (CVE-2026-83550) stemming from the blank import of the 'net/http/pprof' package. This unintended inclusion exposes Go debug endpoints on the default metrics listener port without requiring authentication. Any attacker with network access to the postgres-exporter instance - typically within a Kubernetes pod network or cluster environment - can query these endpoints to retrieve sensitive runtime data.

The exposed information includes process arguments, full goroutine stacks, and memory content, which may contain hardcoded database connection strings, credentials, or sensitive application data extracted via heap dumps. Furthermore, an attacker can intentionally initiate CPU profiling tasks, leading to resource exhaustion and denial of service. The impact is significant for environments where internal cluster traffic is not strictly partitioned or where the metrics port is exposed to wider network segments.

Impact

Successful exploitation leads to unauthorized information disclosure, potentially resulting in the compromise of database credentials or internal system configuration details. Additionally, the vulnerability permits denial of service attacks against the exporter, which can disrupt monitoring pipelines and impact observability of the associated PostgreSQL instances.

Recommendation

  • Audit network ingress policies for all pods running postgres-exporter to ensure the metrics port is not exposed to untrusted network segments.
  • Upgrade the postgres-exporter deployment to a version where 'net/http/pprof' has been removed from the build.
  • Implement network-level access control, such as Kubernetes NetworkPolicies, to restrict access to the metrics port to known monitoring server IPs only.
  • Scan memory-resident secrets and configuration to ensure that the risk of credential leakage via heap dumps is mitigated by rotating any potentially exposed database passwords.

Immediate actions

Restrict network access to postgres-exporter metrics port via NetworkPolicies

IT Operations 24h

Mitigations

Upgrade postgres-exporter to a patched version once released

immediate IT Operations

CVE-2026-83550