« Back to list

Linuxfoundation

Linuxfoundation Cloudnativepg: vulnerabilities and CVEs

Linuxfoundation Cloudnativepg has 3 published vulnerabilities, 3 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs3
Last 12 months3
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-55769Critical (9.4)0.77%—Aug 20, 2026
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in…
CVE-2026-55765High (8.5)0.50%—Aug 20, 2026
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedded cleartext role passwords in `ALTER ROLE` and `CREATE ROLE`…
CVE-2026-44477Critical (9.4)0.52%—May 28, 2026
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as the postgres…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services2
  2. T1068 Exploitation for Privilege Escalation1
  3. T1552.007 Container API1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Linuxfoundation