Executive brief
PostgreSQL Anonymizer is a tool used to hide sensitive data in databases so it can be safely used for testing or reporting. A security flaw allows users who are supposed to see only masked (hidden) data to bypass these protections by repeatedly calling a specific hashing function. By doing this, an attacker can figure out the secret 'salt' used to scramble the data, allowing them to reverse the anonymization and reveal the original sensitive information.
Technical details
The anon.hash() function in PostgreSQL Anonymizer is missing the 'RESTRICTED' security label, which is required by the extension's masking engine to block access for masked roles. Because the function is defined as SECURITY DEFINER, it can access the superuser-only 'anon.salt' value. An authenticated attacker with a masked role can use anon.hash() as a hashing oracle to collect (input, hash) pairs. This allows for offline brute-force or dictionary attacks to recover the secret salt, subsequently enabling the deanonymization of pseudonymized columns and other hashed data. The issue is resolved in version 3.1.2 by correctly applying the RESTRICTED label to the function.
Affected products
- DALIBO PostgreSQL Anonymizer < 3.1.2
Timeline
- 2026-06-30: disclosed
- 2026-06-30: advisory