PatchSiren

kedacore CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM kedacore CVE published 2026-08-21

CVE-2026-53572

KEDA, a Kubernetes-based Event Driven Autoscaling component, is vulnerable to connection string injection attacks prior to version 2.20.0. An attacker could inject host or sslmode parameters, redirecting the database connection to an attacker-controlled server, exposing credentials, or disabling intended TLS protection. Organizations using KEDA for event-driven autoscaling, especially those with PostgreSQ [truncated]