# Pgpool-II patches seven watchdog and certificate-authentication vulnerabilities

Pgpool-II security releases across five maintained branches address seven flaws in watchdog message handling, client certificate authentication and leader election, including memory corruption and authentication bypass risks.

Pgpool-II operators should upgrade to the October 1 security releases and review watchdog network exposure and certificate-authentication configuration.

- Status: Active
- Published: 2026-10-12T06:08:54+13:00
- Updated: 2026-10-12T06:08:54+13:00
- Categories: Cloud & Infrastructure, Deployment & DevOps, Databases & Storage
- Tags: client certificates, failover, Pgpool-II, PostgreSQL, security
- Canonical HTML: https://beyondthe.news/dossiers/pgpool-ii-october-2026-seven-security-cves-watchdog-certificate

## What changed

On October 1, 2026, Pgpool-II maintainers released 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 with fixes for seven vulnerabilities (CVE-2026-92867 through CVE-2026-92873). Watchdog failover messages can trigger arbitrary memory writes, array overflow, stack corruption and crash paths. A certificate common-name NUL-byte handling flaw can permit a malicious certificate-authenticated client to impersonate another user without a password. Other bugs include heartbeat information disclosure and a watchdog leader-promotion authentication bypass.

## Why it matters

Pgpool-II commonly sits between applications and PostgreSQL for pooling, load balancing and automatic failover. Bugs in cluster messaging and certificate identity checks can affect the integrity and availability of database routing, not just a routine library dependency. Operators should patch all affected supported branches and restrict watchdog communication to trusted peers.

## Watchdog memory safety and leader election

Malformed watchdog messages affect memory boundaries and failover processing. Separate vulnerabilities can crash a process, disclose heartbeat information or bypass leader promotion authentication. Network exposure and configured watchdog topology determine reachable attack paths.

## Certificate identity bypass

A NUL byte in the X.509 Common Name is improperly handled when clients use certificate authentication, creating a potential cross-user authentication bypass under that mode.

## Patch across maintained branches

The project shipped coordinated fixes for branches 4.7, 4.6, 4.5, 4.4 and 4.3. Teams should identify the installed Pgpool-II branch and update to its corresponding fixed point release.

## Verify operational behaviour

Stage the update against representative failover, heartbeat and client certificate flows. Recheck network ACLs, watchdog authentication keys, connection pooling and rollback procedures.

## Key details

- Security releases dated October 1, 2026.
- Fixed branches: 4.7.3, 4.6.8, 4.5.13, 4.4.18, 4.3.21.
- Seven CVEs: CVE-2026-92867 to CVE-2026-92873.
- Watchdog memory corruption, information disclosure and leader election bypass.
- Certificate CN NUL-byte user impersonation under certificate auth.

## Builder takeaways

- Upgrade Pgpool-II to the fixed point release for your branch.
- Keep watchdog peer messaging off untrusted networks and audit authentication settings.
- Test failover and client certificate flows after patching.
- Do not infer remote exploitability or active exploitation beyond the maintainer advisory.

## What to watch

- Distribution packaging of patched Pgpool-II branches.
- Maintainer follow-up exploit-prerequisite details or new advisories.

## Uncertainties

- The public notice does not establish active exploitation.
- Impact depends on watchdog network reachability and whether client certificate authentication is configured.

## Sources

- [Pgpool-II coordinated security releases](https://www.postgresql.org/about/news/pgpool-ii-473-468-4513-4418-and-4321-released-3390/) — Pgpool Global Development Group · primary release · 2026-10-01T00:00:00+13:00. Seven CVE descriptions and patched versions.
- [Pgpool-II official release notes](https://www.pgpool.net/docs/latest/en/html/release.html) — Pgpool Global Development Group · primary release · 2026-10-01T00:00:00+13:00. Detailed maintenance release information.

