Key details

  1. Security releases dated October 1, 2026.
  2. Fixed branches: 4.7.3, 4.6.8, 4.5.13, 4.4.18, 4.3.21.
  3. Seven CVEs: CVE-2026-92867 to CVE-2026-92873.
  4. Watchdog memory corruption, information disclosure and leader election bypass.
  5. Certificate CN NUL-byte user impersonation under certificate auth.

What builders should take away

  1. Upgrade Pgpool-II to the fixed point release for your branch.
  2. Keep watchdog peer messaging off untrusted networks and audit authentication settings.
  3. Test failover and client certificate flows after patching.
  4. Do not infer remote exploitability or active exploitation beyond the maintainer advisory.

What changed

On October 1, 2026, Pgpool-II maintainers released 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 with fixes for seven vulnerabilities (CVE-2026-92867 through CVE-2026-92873). Watchdog failover messages can trigger arbitrary memory writes, array overflow, stack corruption and crash paths. A certificate common-name NUL-byte handling flaw can permit a malicious certificate-authenticated client to impersonate another user without a password. Other bugs include heartbeat information disclosure and a watchdog leader-promotion authentication bypass.

Why it matters

Pgpool-II commonly sits between applications and PostgreSQL for pooling, load balancing and automatic failover. Bugs in cluster messaging and certificate identity checks can affect the integrity and availability of database routing, not just a routine library dependency. Operators should patch all affected supported branches and restrict watchdog communication to trusted peers.

Watchdog memory safety and leader election

Malformed watchdog messages affect memory boundaries and failover processing. Separate vulnerabilities can crash a process, disclose heartbeat information or bypass leader promotion authentication. Network exposure and configured watchdog topology determine reachable attack paths.

Certificate identity bypass

A NUL byte in the X.509 Common Name is improperly handled when clients use certificate authentication, creating a potential cross-user authentication bypass under that mode.

Patch across maintained branches

The project shipped coordinated fixes for branches 4.7, 4.6, 4.5, 4.4 and 4.3. Teams should identify the installed Pgpool-II branch and update to its corresponding fixed point release.

Verify operational behaviour

Stage the update against representative failover, heartbeat and client certificate flows. Recheck network ACLs, watchdog authentication keys, connection pooling and rollback procedures.

What to watch next

  • Distribution packaging of patched Pgpool-II branches.
  • Maintainer follow-up exploit-prerequisite details or new advisories.

Still unclear

  • The public notice does not establish active exploitation.
  • Impact depends on watchdog network reachability and whether client certificate authentication is configured.

Sources

Direct reading behind this dossier.

2 sources

Discussion

Discussion is reader-contributed. Comments are not part of the BTN dossier or its editorial evidence.

0 visible comments

Join the discussion

Keep comments useful and relevant. Reader contributions may be moderated and are not BTN editorial evidence.

Sign in to comment