---
id: CVE-2026-54711
title: 'PGHoard: Password written to debug log'
summary: 'PGHoard: Password written to debug log'
severity: low
cwe:
  - CWE-532
vendor: pghoard
product: pghoard
affected:
  - pghoard <= 2.1.0
published: '2026-06-18'
updated: '2026-06-18'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-mpx4-jmpr-vm8v'
references:
  - url: >-
      https://github.com/Aiven-Open/pghoard/security/advisories/GHSA-mpx4-jmpr-vm8v
  - url: 'https://github.com/advisories/GHSA-mpx4-jmpr-vm8v'
tags:
  - ghsa
  - pip
ingestedAt: '2026-06-19T03:39:00.799Z'
ecosystem: pip
---

## Overview

### Impact
When using .pgpass, database connection information including the username and password will be logged at the debug level.

### Patches
Upgrade to version 2.7.1 or greater.

### Workarounds
Filter out debug-level logs.

### References
This issue was discovered by BugCrowd user DRAKOKORIAN.

## Affected packages

- `pghoard <= 2.1.0`

## Remediation

Refer to the advisory for the patched release.
