Published:2026/09/29  Last Updated:2026/09/29

JVN#22475874
Multiple vulnerabilities in Pgpool-II

Overview

Pgpool-II provided by Pgpool Global Development Group contains multiple vulnerabilities.

Products Affected

CVE-2026-92867, CVE-2026-92869, CVE-2026-92870, CVE-2026-92871, CVE-2026-92872, CVE-2026-92873

  • Pgpool-II versions 4.7.0 to 4.7.2
  • Pgpool-II versions 4.6.0 to 4.6.7
  • Pgpool-II versions 4.5.0 to 4.5.12
  • Pgpool-II versions 4.4.0 to 4.4.17
  • Pgpool-II versions 4.3.0 to 4.3.20
  • All versions from Pgpool-II 3.5.x series through 4.2.x series
CVE-2026-92868
  • Pgpool-II versions 4.7.0 to 4.7.2
  • Pgpool-II versions 4.6.0 to 4.6.7
  • Pgpool-II versions 4.5.0 to 4.5.12
  • Pgpool-II versions 4.4.0 to 4.4.17
  • Pgpool-II versions 4.3.0 to 4.3.20
  • All versions from Pgpool-II 4.0.x series through 4.2.x series

Description

Pgpool-II provided by Pgpool Global Development Group contains multiple vulnerabilities listed below:

  • Out-of-bounds Write (CWE-787)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 8.8
    • CVE-2026-92867
  • Improper Certificate Validation (CWE-295)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 6.9
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Base Score 6.5
    • CVE-2026-92868
  • Out-of-bounds Write (CWE-787)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Base Score 7.1
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Base Score 6.5
    • CVE-2026-92869
  • Stack-based Buffer Overflow (CWE-121)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Base Score 7.5
    • CVE-2026-92870
  • NULL Pointer Dereference (CWE-476)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Base Score 7.5
    • CVE-2026-92871
  • Insertion of Sensitive Information into Log File (CWE-532)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 5.3
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Base Score 4.3
    • CVE-2026-92872
  • Incorrect Implementation of Authentication Algorithm (CWE-303)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Base Score 6.9
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Base Score 7.3
    • CVE-2026-92873

Impact

  • Abnormal process termination, and arbitrary code execution (CVE-2026-92867)
  • Client certificate authentication bypass (CVE-2026-92868)
  • Abnormal process termination (CVE-2026-92869, CVE-2026-92870)
  • Abnormal termination of the watchdog process (CVE-2026-92871)
  • Cluster information leak (CVE-2026-92872)
  • Promotion of an arbitrary watchdog node to the leader node (CVE-2026-92873)

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.
The following versions are released to address the vulnerabilities:

  • Pgpool-II 4.7.3
  • Pgpool-II 4.6.8
  • Pgpool-II 4.5.13
  • Pgpool-II 4.4.18
  • Pgpool-II 4.3.21
Support for Pgpool-II versions 3.5 through 4.2 has ended and no further fixes will be released; therefore, if you are using a version prior to 4.3, upgrading to the latest version mentioned above is recommended.

Vendor Status

Vendor Link
Pgpool Global Development Group Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 officially released

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Emond Papegaaij of Topicus Security reported these vulnerabilities to Pgpool Global Development Group and coordinated. Pgpool Global Development Group and JPCERT/CC published respective advisories in order to notify users of this vulnerability.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-92867
CVE-2026-92868
CVE-2026-92869
CVE-2026-92870
CVE-2026-92871
CVE-2026-92872
CVE-2026-92873
JVN iPedia JVNDB-2026-000140