Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 officially released
Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18, 4.3.21 officially released.
This release includes security fixes.
-
A vulnerability in watchdog message processing during failover in Pgpool-II allows an attacker to write an arbitrary 32-bit value to an arbitrary memory address by sending a malformed message. (CVE-2026-92867)
-
When a client connects to Pgpool-II using certificate authentication, Pgpool-II does not properly handle NUL bytes (\0) in the domain name in the Common Name (CN) field of the client’s X.509 certificate. This vulnerability allows a malicious client to connect to the Pgpool-II server as another user without a password. (CVE-2026-92868)
-
A vulnerability in watchdog message processing in Pgpool-II allows an attacker to overwrite memory beyond the boundaries of fixed-size arrays by sending a malformed message. (CVE-2026-92869)
-
A vulnerability in the handling of failover messages by watchdog in Pgpool-II allows writes of arbitrary-length data to corrupt the stack and crash a Pgpool-II process. (CVE-2026-92870)
-
A NULL pointer dereference vulnerability exists in watchdog inter-node authentication in Pgpool-II. When an authentication key is configured, crafted watchdog messages that omit authentication information are not handled correctly. (CVE-2026-92871)
-
An information disclosure vulnerability exists in the heartbeat receiver process of Pgpool-II. (CVE-2026-92872)
-
A vulnerability in watchdog promotion processing in Pgpool-II allows an attacker to bypass authentication key checks and promote a watchdog node of their choice to leader. (CVE-2026-92873)
For more details please see the release notes:
http://www.pgpool.net/docs/latest/en/html/release.html
You can download them here.