← Back

CVE-2026-13455

nvd nist
Published: Jun 30, 2026Modified: Jul 6, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007 (Secondary)

Description

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions

Affected (1)

1 product
Postgresql Anonymizer
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.1.2

References (1)

Source: f86ef6dc-4d3a-42ad-8f28-e6d5547a5007
Vendor Advisory

Timeline

No history available yet.