PatchSiren cyber security CVE debrief
CVE-2026-53572 kedacore CVE debrief
CVE-2026-53572 is a vulnerability in KEDA, a Kubernetes-based Event Driven Autoscaling component. The issue allows an attacker to inject host or sslmode parameters into libpq-style connection strings, potentially redirecting the database connection to an attacker-controlled server, exposing credentials, or disabling intended TLS protection. This vulnerability is fixed in version 2.20.0.
- Vendor
- kedacore
- Product
- keda
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-21
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-08-21
- Advisory updated
- 2026-09-25
Who should care
Defenders responsible for Kubernetes clusters and KEDA deployments should assess exposure and prioritize upgrading to version 2.20.0 if necessary. This includes operators, platform teams, vulnerability management teams, and security teams who need to verify KEDA version and apply necessary updates to prevent potential database connection string injection, exposure of credentials, or disablement of intended TLS protection.
Why it matters
CVE-2026-53572 is a vulnerability in KEDA that allows for potential database connection string injection, exposing credentials, or disabling intended TLS protection. Defenders should prioritize verifying KEDA version and upgrading to 2.20.0 if necessary.
- Potential database connection string injection
- Possible exposure of credentials
- Potential disablement of intended TLS protection
- Verification of KEDA version and upgrade to 2.20.0
Technical summary
The pkg/scalers/postgresql_scaler.go file in KEDA constructs libpq-style connection strings from tenant-controlled host, port, userName, dbName, sslmode, and password values. However, the escapePostgreConnectionParameter() function only quotes values containing a literal space, allowing tabs, newlines, carriage returns, form feeds, vertical tabs, quotes, and backslashes to create additional key-value tokens when parsed by pgx. This allows an attacker to inject host or sslmode parameters, potentially redirecting the database connection to an attacker-controlled server, exposing credentials, or disabling intended TLS protection.
Defensive priority
Defenders should prioritize verifying KEDA version and upgrading to 2.20.0 if necessary.
Recommended defensive actions
- Verify KEDA version and upgrade to 2.20.0 if necessary
- Review and restrict access to TriggerAuthentication and ScaledObject resources
- Monitor database connections for suspicious activity
- Confirm whether affected KEDA deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The vulnerability is caused by the pkg/scalers/postgresql_scaler.go file constructing libpq-style connection strings from tenant-controlled values without proper escaping. The issue is fixed in version 2.20.0.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-53572 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-53572
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-53572 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53572
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/kedacore/keda/commit/703de9dec86cb25b6ecfa4948880a90487344d3f
-
Source reference
Unverified legacy reference
URL: https://github.com/kedacore/keda/issues/7784
-
Source reference
Unverified legacy reference
URL: https://github.com/kedacore/keda/pull/7787
-
Source reference
Unverified legacy reference
URL: https://github.com/kedacore/keda/releases/tag/v2.20.0
-
Source reference
Unverified legacy reference
URL: https://github.com/kedacore/keda/security/advisories/GHSA-6w3m-4hhp-775q
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.