{"id":"CVE-2026-54711","title":"PGHoard: Password written to debug log","summary":"PGHoard: Password written to debug log","severity":"low","cwe":["CWE-532"],"vendor":"pghoard","product":"pghoard","affected":["pghoard <= 2.1.0"],"published":"2026-06-18","updated":"2026-06-18","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-mpx4-jmpr-vm8v","references":[{"url":"https://github.com/Aiven-Open/pghoard/security/advisories/GHSA-mpx4-jmpr-vm8v"},{"url":"https://github.com/advisories/GHSA-mpx4-jmpr-vm8v"}],"tags":["ghsa","pip"],"ingestedAt":"2026-06-19T03:39:00.799Z","ecosystem":"pip","slug":"CVE-2026-54711","body":"## Overview\n\n### Impact\nWhen using .pgpass, database connection information including the username and password will be logged at the debug level.\n\n### Patches\nUpgrade to version 2.7.1 or greater.\n\n### Workarounds\nFilter out debug-level logs.\n\n### References\nThis issue was discovered by BugCrowd user DRAKOKORIAN.\n\n## Affected packages\n\n- `pghoard <= 2.1.0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"sunlit","depthScore":14,"depthScoreParts":{"impact":13.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}