Fetching from the wire…
Security2026-08-13 · source-backed
arXiv 2608.11730 shows that row-level security in PostgreSQL leaks through timing, letting an attacker enumerate unknown attribute values and recover full records via binary search over large domains. Elasticsearch/OpenSearch DLS is worse: scoring and prefix-expansion side channels extract indexed terms and approximate document text. If you built multi-tenant isolation on RLS and called it done, this is your reading for the week. Rich predicates are what convert membership leakage into recovery.
Each link below shares sources, entities, or timing with this story.
Shared entity: PostgreSQL / Same source domain / Earlier coverage / Tension
Both cover PostgreSQL; reported by the same outlet (arxiv.org); earlier PostgreSQL coverage from 2026-08-06.
Shared entity: PostgreSQL / Same source domain / Earlier coverage
Both cover PostgreSQL; reported by the same outlet (arxiv.org); earlier PostgreSQL coverage from 2026-03-02.
Same source domain / Shared topic / Tension
Reported by the same outlet (arxiv.org); overlapping topics (attacker, channel); pushes against this story (against).
Same source domain / Shared topic / Downstream implication
Reported by the same outlet (arxiv.org); overlapping topics (extract, full); traces where this leads (implication).
Shared entity: PostgreSQL / Tension
Both cover PostgreSQL; pushes against this story (against).
Same source domain / Shared topic
Reported by the same outlet (arxiv.org); overlapping topics (attacker, record).
Reported by the same outlet (arxiv.org); overlapping topics (convert, full).
Reported by the same outlet (arxiv.org); overlapping topics (full, record).