CVE-2026-54711Low▾ SunlitPGHoard: Password written to debug log
▾ Sunlit zone — Low / medium · no exploitation signal
impact 13.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
When using .pgpass, database connection information including the username and password will be logged at the debug level.
Upgrade to version 2.7.1 or greater.
Filter out debug-level logs.
This issue was discovered by BugCrowd user DRAKOKORIAN.
pghoard <= 2.1.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-56142Medium· 6.5PGHoard Path Traversal vulnerability
CVE-2019-1953Medium· 6.5A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to view a password in clear text
CVE-2024-23686Medium· 5.3DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.
CVE-2023-43261High· 7.5An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
CVE-2026-86049High· 7.1Jupyter Server is the backend for Jupyter web applications
CVE-2025-66236High· 7.5Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI