CVE-2026-53572 | KedaCore Keda 2.17.3/2.18.2/2.18.3 PostgreSQL Scaler postgresql_scaler.go escapePostgreConnectionParameter host/port/userName/dbName/sslmode/password code injection

SecurityVulns

A vulnerability, which was classified as problematic, has been found in KedaCore Keda 2.17.3/2.18.2/2.18.3. This vulnerability affects the function escapePostgreConnectionParameter of the file pkg/scalers/postgresql_scaler.go of the component PostgreSQL Scaler. The manipulation of the argument host/port/userName/dbName/sslmode/password leads to code injection.

This vulnerability is traded as CVE-2026-53572. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More