highVulnerability

GHSA-5x78-73v4-xg6w

A malicious, compromised, or man-in-the-middle server can supply an arbitrarily large SCRAM-SHA-256 PBKDF2 iteration count during authentication. The client runs it inline with no upper bound, pinning a `tokio` worker thread for minutes per connection, possibly stalling the whole async runtime. Applications that connect only to a trusted database are not exposed; the risk applies to clients that may connect to untrusted or user-supplied servers, or whose connection can be intercepted by a man-in-the-middle.

Properties

ghsa_id
GHSA-5x78-73v4-xg6w
severity
high
summary
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
cve_id
GHSA-5x78-73v4-xg6w
is_ghsa_only
true
ghsa_published
2026-08-24T19:43:31Z
source_url
https://github.com/advisories/GHSA-5x78-73v4-xg6w
ghsa_updated
2026-08-24T19:43:32Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]rust/postgres-protocol

AFFECTS (1)

[Software]rust/postgres-protocol

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-5x78-73v4-xg6w — Ninja Signal Threat Intelligence | Ninja Signal