Vulnerability Description
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. The problem is resolved in PostgreSQL Anonymizer 3.1.2 and later versions
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dalibo | Postgresql Anonymizer | <= 3.1.2 |
Related Weaknesses (CWE)
References
- https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/649Vendor Advisory
FAQ
What is CVE-2026-13455?
CVE-2026-13455 is a vulnerability with a CVSS score of 4.3 (MEDIUM). PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-forc...
How severe is CVE-2026-13455?
CVE-2026-13455 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-13455?
Check the references section above for vendor advisories and patch information. Affected products include: Dalibo Postgresql Anonymizer.