PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-53572 kedacore CVE debrief

CVE-2026-53572 is a vulnerability in KEDA, a Kubernetes-based Event Driven Autoscaling component. The issue allows an attacker to inject host or sslmode parameters into libpq-style connection strings, potentially redirecting the database connection to an attacker-controlled server, exposing credentials, or disabling intended TLS protection. This vulnerability is fixed in version 2.20.0.

Vendor
kedacore
Product
keda
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-21
Original CVE updated
2026-09-25
Advisory published
2026-08-21
Advisory updated
2026-09-25

Who should care

Defenders responsible for Kubernetes clusters and KEDA deployments should assess exposure and prioritize upgrading to version 2.20.0 if necessary. This includes operators, platform teams, vulnerability management teams, and security teams who need to verify KEDA version and apply necessary updates to prevent potential database connection string injection, exposure of credentials, or disablement of intended TLS protection.

Why it matters

CVE-2026-53572 is a vulnerability in KEDA that allows for potential database connection string injection, exposing credentials, or disabling intended TLS protection. Defenders should prioritize verifying KEDA version and upgrading to 2.20.0 if necessary.

  • Potential database connection string injection
  • Possible exposure of credentials
  • Potential disablement of intended TLS protection
  • Verification of KEDA version and upgrade to 2.20.0

Technical summary

The pkg/scalers/postgresql_scaler.go file in KEDA constructs libpq-style connection strings from tenant-controlled host, port, userName, dbName, sslmode, and password values. However, the escapePostgreConnectionParameter() function only quotes values containing a literal space, allowing tabs, newlines, carriage returns, form feeds, vertical tabs, quotes, and backslashes to create additional key-value tokens when parsed by pgx. This allows an attacker to inject host or sslmode parameters, potentially redirecting the database connection to an attacker-controlled server, exposing credentials, or disabling intended TLS protection.

Defensive priority

Defenders should prioritize verifying KEDA version and upgrading to 2.20.0 if necessary.

Recommended defensive actions

  • Verify KEDA version and upgrade to 2.20.0 if necessary
  • Review and restrict access to TriggerAuthentication and ScaledObject resources
  • Monitor database connections for suspicious activity
  • Confirm whether affected KEDA deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The vulnerability is caused by the pkg/scalers/postgresql_scaler.go file constructing libpq-style connection strings from tenant-controlled values without proper escaping. The issue is fixed in version 2.20.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-53572 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-53572

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-53572 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-53572

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.