PatchSiren

kedacore CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM kedacore CVE published 2026-08-21

CVE-2026-53572

CVE-2026-53572 is a vulnerability in KEDA, a Kubernetes-based Event Driven Autoscaling component. The issue allows an attacker to inject host or sslmode parameters into libpq-style connection strings, potentially redirecting the database connection to an attacker-controlled server, exposing credentials, or disabling intended TLS protection. This vulnerability is fixed in version 2.20.0.