Aiven operates a managed data-services platform that abstracts and integrates open-source databases and streaming systems, with its vulnerability profile centered on tools like Aiven DB Migrate, Karapace, and JournalPump that bridge configuration, schema management, and data movement workflows. The recurring weakness classes—path traversal, cleartext transmission, and improper access control—reflect the sensitivity of data in transit and at rest across a platform where configuration and credentialing are high-value attack surfaces. Defenders tracking this vendor should prioritize authentication and transport-layer hardening in deployment configurations, while live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aiven over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-55282HIGH aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows a user to elevate to superuser inside PostgreSQL dat | Aug 18, 2025 | 7.2 | 28 | NO | NO |
CVE-2023-32305HIGH aiven-extras is a PostgreSQL extension. Versions prior to 1.1.9 contain a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use t | May 12, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-55283HIGH aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows elevation to superuser inside PostgreSQL databases d | Aug 18, 2025 | 7.2 | 26 | NO | NO |
CVE-2025-67745HIGH MyHoard is a daemon for creating, managing and restoring MySQL backups. Starting in version 1.0.1 and prior to version 1.3.0, in some cases, myhoard logs the whole backup info, inc | Dec 18, 2025 | 7.5 | 24 | NO | NO |
CVE-2026-29190MEDIUM Karapace is an open-source implementation of Kafka REST and Schema Registry. Prior to version 6.0.0, there is a Path Traversal vulnerability in the backup reader (backup/backends/v | Mar 7, 2026 | 5.3 | 20 | NO | NO |
CVE-2023-51390HIGH journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of | Dec 21, 2023 | 7.5 | 20 | NO | NO |
CVE-2026-39961MEDIUM Aiven Operator allows you to provision and manage Aiven Services from your Kubernetes cluster. From 0.31.0 to before 0.37.0, a developer with create permission on ClickhouseUser CR | Apr 9, 2026 | 4.9 | 19 | NO | NO |
CVE-2026-25999MEDIUM Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to tr | Feb 11, 2026 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aiven.
Media articles that mention a CVE ID that affects a product developed by Aiven — matched by CVE ID, not by vendor name.