StackRadar

CVE-2026-44477

Critical

Advisory

Published 11 May 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.9
base score, highest
EPSS
0.005
40th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
10
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
1 of 1
affected package

CloudNativePG's metrics exporter allows privilege escalation to PostgreSQL superuser and OS RCE

Carried by container images the latest versions of 10 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
github.com/cloudnative-pg/cloudnative-pggolangv1.17.1, v1.20.0, v1.21.1, v1.25.0+2 more1.28.37
OSV records
GHSA-423p-g724-fr39
Also known as
GO-2026-5106

Charts affected

10 by stars
ChartLatestAffected imagesRadar Score
qgis-serverqgis-serverVerified publisher0.1.101 of 3See more

qgis-server qgis-server 0.1.10

1 of the 3 container images this version deploys carry CVE-2026-44477.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
github.com/cloudnative-pg/cloudnative-pg@v1.25.1
1.28.3

Open the chart page →

5,435
cnpg-sandboxcloudnative-pgVerified publisher0.6.11 of 6See more

cnpg-sandbox cloudnative-pg 0.6.1

1 of the 6 container images this version deploys carry CVE-2026-44477.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
github.com/cloudnative-pg/cloudnative-pg@v1.17.1
1.28.3

Open the chart page →

7,583
kube-site-followerkube-site-follower0.1.141 of 2See more

kube-site-follower kube-site-follower 0.1.14

1 of the 2 container images this version deploys carry CVE-2026-44477.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
github.com/cloudnative-pg/cloudnative-pg@v1.25.0
1.28.3

Open the chart page →

902
galaxy-depscloudve1.1.11 of 7See more

galaxy-deps cloudve 1.1.1

1 of the 7 container images this version deploys carry CVE-2026-44477.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
github.com/cloudnative-pg/cloudnative-pg@v1.25.0
1.28.3

Open the chart page →

10,531
cloudnative-pgjouveVerified publisher0.27.01 of 1See more

cloudnative-pg jouve 0.27.0

1 of the 1 container images this version deploys carry CVE-2026-44477.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.28.034198e85b6e6
github.com/cloudnative-pg/cloudnative-pg@v1.28.0
1.28.3

Open the chart page →

647
cloudnative-pgkube-site-follower0.23.01 of 1See more

cloudnative-pg kube-site-follower 0.23.0

1 of the 1 container images this version deploys carry CVE-2026-44477.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
github.com/cloudnative-pg/cloudnative-pg@v1.25.0
1.28.3

Open the chart page →

902
cloudnative-pgnineinfra-charts0.19.11 of 1See more

cloudnative-pg nineinfra-charts 0.19.1

1 of the 1 container images this version deploys carry CVE-2026-44477.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.21.19f707d91de1c
github.com/cloudnative-pg/cloudnative-pg@v1.21.1
1.28.3

Open the chart page →

1,187
nineinfranineinfra-charts0.7.01 of 1See more

nineinfra nineinfra-charts 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-44477.

Container imageDigestPackageFixed in
nineinfra/nineinfra:v0.7.0d4aad414eccd
github.com/cloudnative-pg/cloudnative-pg@v1.21.1
1.28.3

Open the chart page →

1,120
cloudnative-pgradar-baseVerified publisher0.23.21 of 1See more

cloudnative-pg radar-base 0.23.2

1 of the 1 container images this version deploys carry CVE-2026-44477.

Container imageDigestPackageFixed in
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
github.com/cloudnative-pg/cloudnative-pg@v1.25.1
1.28.3

Open the chart page →

849
apache-shardingsphere-operator-chartsshardingsphere0.3.01 of 2See more

apache-shardingsphere-operator-charts shardingsphere 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-44477.

Container imageDigestPackageFixed in
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
github.com/cloudnative-pg/cloudnative-pg@v1.20.0
1.28.3

Open the chart page →

1,698

Container images carrying it

7 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.0a27779ed1085
github.com/cloudnative-pg/cloudnative-pg@v1.25.0
1.28.3
3
ghcr.io/cloudnative-pg/cloudnative-pg:1.25.1b5210df46c05
github.com/cloudnative-pg/cloudnative-pg@v1.25.1
1.28.3
2
apache/shardingsphere-operator:0.3.0ffe68d6b99c0
github.com/cloudnative-pg/cloudnative-pg@v1.20.0
1.28.3
1
nineinfra/nineinfra:v0.7.0d4aad414eccd
github.com/cloudnative-pg/cloudnative-pg@v1.21.1
1.28.3
1
ghcr.io/cloudnative-pg/cloudnative-pg:1.28.034198e85b6e6
github.com/cloudnative-pg/cloudnative-pg@v1.28.0
1.28.3
1
ghcr.io/cloudnative-pg/cloudnative-pg:1.17.14dd365800b62
github.com/cloudnative-pg/cloudnative-pg@v1.17.1
1.28.3
1
ghcr.io/cloudnative-pg/cloudnative-pg:1.21.19f707d91de1c
github.com/cloudnative-pg/cloudnative-pg@v1.21.1
1.28.3
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.