MEDIUM
kedacore
CVE published 2026-08-21
CVE-2026-53572
CVE-2026-53572 is a vulnerability in KEDA, a Kubernetes-based Event Driven Autoscaling component. The issue allows an attacker to inject host or sslmode parameters into libpq-style connection strings, potentially redirecting the database connection to an attacker-controlled server, exposing credentials, or disabling intended TLS protection. This vulnerability is fixed in version 2.20.0.