chiprook
← Security
SecurityOctober 4, 2026, 11:40

Pgpool-II 3.5.x–4.2.x: seven CVEs with no patches as support ends

JVN#22475874 lists seven vulnerabilities in Pgpool-II, including an out-of-bounds write with a CVSS score of 8.8 and a client certificate authentication bypass. Fixes exist only for maintained branches 4.3–4.7, while versions 3.5.x through 4.2.x will receive no patches.

Pgpool-II 3.5.x–4.2.x: seven CVEs with no patches as support ends
#Pgpool-II#PostgreSQL
Read next
Business

HMRC paid Capgemini another £4.2B after vowing to end the relationship

Security

Microsoft fixes 974 CVEs in September 2026 Patch Tuesday

Security

Cisco patches five CVEs in Secure Email Gateway and Email and Web Manager

Software

Debian 13 Trixie Kernel Security Update Patches Over 1300 CVEs