Linuxfoundation
Linuxfoundation Cloudnativepg: vulnerabilities and CVEs
Linuxfoundation Cloudnativepg has 3 published vulnerabilities, 3 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs3
Last 12 months3
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55769 | Critical (9.4) | 0.77% | — | Aug 20, 2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in… |
| CVE-2026-55765 | High (8.5) | 0.50% | — | Aug 20, 2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE`… |
| CVE-2026-44477 | Critical (9.4) | 0.52% | — | May 28, 2026 | CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.