<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Prometheus-Community - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/prometheus-community/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 20:57:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/prometheus-community/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure via Exposed net/http/pprof in postgres-exporter</title><link>https://feed.craftedsignal.io/briefs/2026-10-postgres-exporter-pprof/</link><pubDate>Tue, 06 Oct 2026 20:57:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-postgres-exporter-pprof/</guid><description>An unauthenticated exposure of Go pprof debug endpoints in postgres-exporter allows remote attackers to perform information disclosure of credentials and process memory or trigger a denial of service.</description><content:encoded><![CDATA[<p>The postgres-exporter software contains a vulnerability (CVE-2026-83550) stemming from the blank import of the 'net/http/pprof' package. This unintended inclusion exposes Go debug endpoints on the default metrics listener port without requiring authentication. Any attacker with network access to the postgres-exporter instance - typically within a Kubernetes pod network or cluster environment - can query these endpoints to retrieve sensitive runtime data.</p>
<p>The exposed information includes process arguments, full goroutine stacks, and memory content, which may contain hardcoded database connection strings, credentials, or sensitive application data extracted via heap dumps. Furthermore, an attacker can intentionally initiate CPU profiling tasks, leading to resource exhaustion and denial of service. The impact is significant for environments where internal cluster traffic is not strictly partitioned or where the metrics port is exposed to wider network segments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to unauthorized information disclosure, potentially resulting in the compromise of database credentials or internal system configuration details. Additionally, the vulnerability permits denial of service attacks against the exporter, which can disrupt monitoring pipelines and impact observability of the associated PostgreSQL instances.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Audit network ingress policies for all pods running postgres-exporter to ensure the metrics port is not exposed to untrusted network segments.</li>
<li>Upgrade the postgres-exporter deployment to a version where 'net/http/pprof' has been removed from the build.</li>
<li>Implement network-level access control, such as Kubernetes NetworkPolicies, to restrict access to the metrics port to known monitoring server IPs only.</li>
<li>Scan memory-resident secrets and configuration to ensure that the risk of credential leakage via heap dumps is mitigated by rotating any potentially exposed database passwords.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>