Medium severity4.3NVD Advisory· Published Jun 30, 2026· Updated Jul 6, 2026
CVE-2026-13455
CVE-2026-13455
Description
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions
Affected products
3cpe:2.3:a:dalibo:postgresql_anonymizer:*:*:*:*:*:postgresql:*:*+ 1 more
- cpe:2.3:a:dalibo:postgresql_anonymizer:*:*:*:*:*:postgresql:*:*range: <=3.1.2
- (no CPE)range: >=3.1.2
- Range: >=3.1.2
Patches
Vulnerability mechanics
References
1- gitlab.com/dalibo/postgresql_anonymizer/-/issues/649nvdVendor Advisory
News mentions
0No linked articles in our index yet.