SQL Injection Affecting github.com/kedacore/keda/pkg/scalers package, versions >=0.0.0


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.32% (25th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMKEDACOREKEDAPKGSCALERS-17895042
  • published8 Jul 2026
  • disclosed7 Jul 2026
  • creditUnknown

Introduced: 7 Jul 2026

CVE-2026-53572  (opens in a new tab)
CWE-74  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

There is no fixed version for github.com/kedacore/keda/pkg/scalers.

Overview

Affected versions of this package are vulnerable to SQL Injection via the escapePostgreConnectionParameter function. An attacker can inject arbitrary PostgreSQL connection parameters by supplying specially crafted values containing non-space whitespace or backslash characters, which are not properly escaped. This can allow the attacker to force insecure connection settings, redirect connections to attacker-controlled hosts, or append additional runtime parameters.

CVSS Base Scores

version 4.0
version 3.1