Published:2026/09/29 Last Updated:2026/09/29
JVN#22475874
Multiple vulnerabilities in Pgpool-II
Overview
Pgpool-II provided by Pgpool Global Development Group contains multiple vulnerabilities.
Products Affected
CVE-2026-92867, CVE-2026-92869, CVE-2026-92870, CVE-2026-92871, CVE-2026-92872, CVE-2026-92873
- Pgpool-II versions 4.7.0 to 4.7.2
- Pgpool-II versions 4.6.0 to 4.6.7
- Pgpool-II versions 4.5.0 to 4.5.12
- Pgpool-II versions 4.4.0 to 4.4.17
- Pgpool-II versions 4.3.0 to 4.3.20
- All versions from Pgpool-II 3.5.x series through 4.2.x series
- Pgpool-II versions 4.7.0 to 4.7.2
- Pgpool-II versions 4.6.0 to 4.6.7
- Pgpool-II versions 4.5.0 to 4.5.12
- Pgpool-II versions 4.4.0 to 4.4.17
- Pgpool-II versions 4.3.0 to 4.3.20
- All versions from Pgpool-II 4.0.x series through 4.2.x series
Description
Pgpool-II provided by Pgpool Global Development Group contains multiple vulnerabilities listed below:
- Out-of-bounds Write (CWE-787)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.7
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 8.8
- CVE-2026-92867
- Improper Certificate Validation (CWE-295)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Base Score 6.9
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Base Score 6.5
- CVE-2026-92868
- Out-of-bounds Write (CWE-787)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Base Score 7.1
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Base Score 6.5
- CVE-2026-92869
- Stack-based Buffer Overflow (CWE-121)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Base Score 8.7
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Base Score 7.5
- CVE-2026-92870
- NULL Pointer Dereference (CWE-476)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Base Score 8.7
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Base Score 7.5
- CVE-2026-92871
- Insertion of Sensitive Information into Log File (CWE-532)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 5.3
- CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Base Score 4.3
- CVE-2026-92872
- Incorrect Implementation of Authentication Algorithm (CWE-303)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N Base Score 6.9
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Base Score 7.3
- CVE-2026-92873
Impact
- Abnormal process termination, and arbitrary code execution (CVE-2026-92867)
- Client certificate authentication bypass (CVE-2026-92868)
- Abnormal process termination (CVE-2026-92869, CVE-2026-92870)
- Abnormal termination of the watchdog process (CVE-2026-92871)
- Cluster information leak (CVE-2026-92872)
- Promotion of an arbitrary watchdog node to the leader node (CVE-2026-92873)
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
The following versions are released to address the vulnerabilities:
- Pgpool-II 4.7.3
- Pgpool-II 4.6.8
- Pgpool-II 4.5.13
- Pgpool-II 4.4.18
- Pgpool-II 4.3.21
Vendor Status
| Vendor | Link |
| Pgpool Global Development Group | Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 officially released |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Emond Papegaaij of Topicus Security reported these vulnerabilities to Pgpool Global Development Group and coordinated. Pgpool Global Development Group and JPCERT/CC published respective advisories in order to notify users of this vulnerability.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-92867 |
|
CVE-2026-92868 |
|
|
CVE-2026-92869 |
|
|
CVE-2026-92870 |
|
|
CVE-2026-92871 |
|
|
CVE-2026-92872 |
|
|
CVE-2026-92873 |
|
| JVN iPedia |
JVNDB-2026-000140 |