{"id":"CVE-2026-97469","published":"2026-09-25T16:17:30.713","lastModified":"2026-09-29T21:27:41.130","description":"PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A masked role can run a RESTRICTED function when the call is placed inside the sub-select. The problem is resolved in PostgreSQL Anonymizer 3.2.3 and later versions","cvssScore":4.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","cwes":["CWE-328"],"vendors":[],"products":[],"references":[{"url":"https://gitlab.com/dalibo/postgresql_anonymizer/-/issues/685","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}