MEDIUM
kedacore
CVE published 2026-08-21
CVE-2026-53572
KEDA, a Kubernetes-based Event Driven Autoscaling component, is vulnerable to connection string injection attacks prior to version 2.20.0. An attacker could inject host or sslmode parameters, redirecting the database connection to an attacker-controlled server, exposing credentials, or disabling intended TLS protection. Organizations using KEDA for event-driven autoscaling, especially those with PostgreSQ [truncated]