Intel

AIKIDO-2026-10187

github.com/cyberark/secretless-broker is vulnerable to Uncontrolled Resource Consumption

Uncontrolled Resource Consumption Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

20

Low Risk

This Affects:

GOgithub.com/cyberark/secretless-broker
1.0.0 - 1.7.31
Fixed in 1.7.32

TL;DR

Affected versions of this package do not enforce message length limits in the PostgreSQL protocol handler, allowing excessively large startup or authentication messages that can trigger uncontrolled memory allocation and lead to denial-of-service conditions. An attacker could exploit this by sending specially crafted oversized packets to the server, exhausting memory resources and causing performance degradation or service unavailability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/cyberark/secretless-broker is vulnerable to Uncontrolled Resource Consumption in versions 1.0.0 - 1.7.31.

How to fix this

Upgrade the github.com/cyberark/secretless-broker library to the patch version.

Background Info