Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Restrict access to anon.hash() for masked users: SECURITY LABEL FOR anon ON FUNCTION anon.hash(TEXT) IS 'RESTRICTED'.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/649 |
|
Tue, 30 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Jun 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions | |
| Title | PostgreSQL Anonymizer: Unrestricted function can leak the secret salt | |
| Weaknesses | CWE-328 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-06-30T15:57:53.085Z
Reserved: 2026-06-26T18:36:50.872Z
Link: CVE-2026-13455
Updated: 2026-06-30T15:57:14.669Z
No data.
No data.
OpenCVE Enrichment
No data.