Description
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A masked role can run a RESTRICTED function when the call is placed inside the sub-select. The problem is resolved in PostgreSQL Anonymizer 3.2.3 and later versions
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Workaround
Disable dynamic masking
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/685 |
|
History
Fri, 25 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A masked role can run a RESTRICTED function when the call is placed inside the sub-select. The problem is resolved in PostgreSQL Anonymizer 3.2.3 and later versions | |
| Title | PostgreSQL Anonymizer: RESTRICTED functions are reachable through a subLink | |
| Weaknesses | CWE-328 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: PostgreSQL
Published:
Updated: 2026-09-25T16:06:42.100Z
Reserved: 2026-09-24T15:46:30.563Z
Link: CVE-2026-97469
No data.
Status : Received
Published: 2026-09-25T16:17:30.713
Modified: 2026-09-25T16:17:30.713
Link: CVE-2026-97469
No data.
OpenCVE Enrichment
No data.
Weaknesses