Browse all 3 CVE security advisories affecting cloudnative-pg. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-55769 | CloudNativePG: Overriding operators can lead to privilege escalation in CloudNativePG for SQL queries without a fixed `search_path` — cloudnative-pg CWE-426 | 9.4 | Critical | 2026-08-20 |
| CVE-2026-55765 | CloudNativePG: Cleartext role passwords recorded in pg_stat_statements allow privileged tenant roles to recover the PostgreSQL superuser credential and achieve RCE in the database pod — cloudnative-pg CWE-256 | 8.5 | High | 2026-08-20 |
| CVE-2026-44477 | CloudNativePG: Metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE — cloudnative-pg CWE-250 | - | - | 2026-05-28 |
This page lists every published CVE security advisory associated with cloudnative-pg. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.