# CVE-2025-31480

## Summary

- **CVE ID:** CVE-2025-31480
- **Severity:** CRITICAL
- **CVSS Score:** 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-426
- **Published:** Apr 4, 2025
- **Last Modified:** Mar 12, 2026

## Description

aiven-extras is a PostgreSQL extension. This is a privilege escalation vulnerability, allowing elevation to superuser inside PostgreSQL databases that use the aiven-extras package. The vulnerability leverages the format function not being schema-prefixed. Affected users should install 1.1.16 and ensure they run the latest version issuing ALTER EXTENSION aiven_extras UPDATE TO '1.1.16' after installing it. This needs to happen in each database aiven_extras has been installed in.

## Affected Products

- aiven — aiven-extras (< 1.1.16)

## References

- [CNA](https://github.com/aiven/aiven-extras/security/advisories/GHSA-33xh-jqgf-6627)
- [CNA](https://github.com/aiven/aiven-extras/commit/77b5f19a0c1d196bc741ff5c774f85fe7ca3063b)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.48%
- **EPSS Percentile:** 39.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._