CVE-2026-83550 is a vulnerability in Red Hat Multicluster Globalhub
Published on October 6, 2026
Postgres-exporter: net/http/pprof exposed on metrics listener
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A remote attacker within the cluster network can access these endpoints. This allows for information disclosure, potentially revealing process arguments, full goroutine stacks, and sensitive data like database connection strings or passwords from heap dumps. Additionally, repeated CPU profiling through these endpoints can lead to a denial of service.
Vulnerability Analysis
Timeline
Reported to Red Hat.
Made public. 36 days later.
Weakness Type
Active Debug Code
The application is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information. A common development practice is to add "back door" code specifically designed for debugging or testing purposes that is not intended to be shipped or deployed with the application. These back door entry points create security risks because they are not considered during design or testing and fall outside of the expected operating conditions of the application.
Products Associated with CVE-2026-83550
Want to know whenever a new CVE is published for Red Hat Multicluster Globalhub? stack.watch will email you.