What changed
On October 1, 2026, Pgpool-II maintainers released 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 with fixes for seven vulnerabilities (CVE-2026-92867 through CVE-2026-92873). Watchdog failover messages can trigger arbitrary memory writes, array overflow, stack corruption and crash paths. A certificate common-name NUL-byte handling flaw can permit a malicious certificate-authenticated client to impersonate another user without a password. Other bugs include heartbeat information disclosure and a watchdog leader-promotion authentication bypass.
Why it matters
Pgpool-II commonly sits between applications and PostgreSQL for pooling, load balancing and automatic failover. Bugs in cluster messaging and certificate identity checks can affect the integrity and availability of database routing, not just a routine library dependency. Operators should patch all affected supported branches and restrict watchdog communication to trusted peers.
Watchdog memory safety and leader election
Malformed watchdog messages affect memory boundaries and failover processing. Separate vulnerabilities can crash a process, disclose heartbeat information or bypass leader promotion authentication. Network exposure and configured watchdog topology determine reachable attack paths.
Certificate identity bypass
A NUL byte in the X.509 Common Name is improperly handled when clients use certificate authentication, creating a potential cross-user authentication bypass under that mode.
Patch across maintained branches
The project shipped coordinated fixes for branches 4.7, 4.6, 4.5, 4.4 and 4.3. Teams should identify the installed Pgpool-II branch and update to its corresponding fixed point release.
Verify operational behaviour
Stage the update against representative failover, heartbeat and client certificate flows. Recheck network ACLs, watchdog authentication keys, connection pooling and rollback procedures.