
that’s where CVE-2026-53572 was hiding. found a connection string injection vulnerability in KEDA’s PostgreSQL scaler that could enable TLS downgrade or credential exfiltration in multi-tenant Kubernetes environments. the quick fix, now available in v2.20.0. https://github.com/advisories/GHSA-6w3m-4hhp-775q #KEDA #Kubernetes #CNCF #SecurityResearch
Post summary
The post reports a KEDA PostgreSQL scaler connection string injection flaw that could allow TLS downgrade or credential exfiltration, and it announces a quick fix in version 2.20.0.
