Pgpool-II 3.5.x–4.2.x: seven CVEs with no patches as support ends
JVN#22475874 lists seven vulnerabilities in Pgpool-II, including an out-of-bounds write with a CVSS score of 8.8 and a client certificate authentication bypass. Fixes exist only for maintained branches 4.3–4.7, while versions 3.5.x through 4.2.x will receive no patches.
- CVE-2026-92867 is an out-of-bounds write with CVSS 8.8 and code execution risk
- Fixed releases: 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 only
- ZoomEye found 101 internet-visible Pgpool-II instances on September 29, 2026
- Support for branches 3.5 through 4.2 has ended with no backports
Read next
Business