Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Disable dynamic masking
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/685 |
|
Sat, 26 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 26 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dalibo
Dalibo postgresql Anonymizer |
|
| Vendors & Products |
Dalibo
Dalibo postgresql Anonymizer |
Fri, 25 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A masked role can run a RESTRICTED function when the call is placed inside the sub-select. The problem is resolved in PostgreSQL Anonymizer 3.2.3 and later versions | |
| Title | PostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLink | |
| Weaknesses | CWE-328 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-09-25T16:06:42.100Z
Reserved: 2026-09-24T15:46:30.563Z
Link: CVE-2026-97469
Updated: 2026-09-25T16:06:38.931Z
Status : Received
Published: 2026-09-25T16:17:30.713
Modified: 2026-09-25T17:17:21.033
Link: CVE-2026-97469
No data.
OpenCVE Enrichment
Updated: 2026-09-26T11:45:09Z
-
CWE-328
Use of Weak Hash