Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 released.
What happened
Minor releases Pgpool Global Development Group is pleased to announce the availability of following versions of Pgpool-II: 4.7.3 4.6.8 4.5.13 4.4.18 4.3.21 These releases include security fixes. Pgpool-II is a tool to add useful features to PostgreSQL, including: connection pooling load balancing automatic failover and more .
A vulnerability in watchdog message processing during failover in Pgpool-II allows an attacker to write an arbitrary 32-bit value to an arbitrary memory address by sending a malformed message. (CVE-2026-92867 (the public catalogue number for a specific software flaw)) When a client connects to Pgpool-II using certificate authentication, Pgpool-II does not properly handle NUL bytes (\0) in the domain name in the Common Name (CN) field of the client's X.509 certificate.
This vulnerability allows a malicious client to connect to the Pgpool-II server as another user without a password. (CVE-2026-92870) A NULL pointer dereference vulnerability exists in watchdog inter-node authentication in Pgpool-II.
Sources & evidence
- PostgreSQL News Primary / official
Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 released. ↗
https://www.postgresql.org/about/news/pgpool-ii-473-468-4513-4418-and-4321-released-3390/