PT-2026-97495 · Postgresql Global Development Group+1 · Postgresql+1

·

CVE-2026-71461

·

Published

2026-09-23

·

Updated

2026-09-26

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The HostList.list() function catches generic exceptions and returns the error string verbatim. An authenticated user can exploit this via the host filter parameter to trigger a Django FieldError, which leaks the complete Host model relation graph and internal reverse accessors, or a PostgreSQL DataError, which leaks raw database error strings. This can be achieved using primitives such as credential search=x to dump the ORM schema or name regex=[bad to reflect PostgreSQL errors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71461

Affected Products

Django
Postgresql