VulnSea

Pgpool-II vulnerabilities

CVEs whose affected-version data names the Pgpool-II package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-92873High· 7.3
today

Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.

Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node.

▾ TwilightPgpool Global Development Group · Pgpool-IIvia NVD
CVE-2026-92868Medium· 6.5
today

An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.

An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication.

▾ SunlitPgpool Global Development Group · Pgpool-IIvia NVD
CVE-2026-92867High· 8.8
today

An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.

An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution.

▾ TwilightPgpool Global Development Group · Pgpool-IIvia NVD
CVE-2026-92870High· 7.5
today

A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.

A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.

▾ TwilightPgpool Global Development Group · Pgpool-IIvia NVD
CVE-2026-92869Medium· 6.5
today

An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.

An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.

▾ SunlitPgpool Global Development Group · Pgpool-IIvia NVD
CVE-2026-92871High· 7.5
today

A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.

A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.

▾ TwilightPgpool Global Development Group · Pgpool-IIvia NVD
CVE-2026-92872Medium· 4.3
today

Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.

Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.

▾ SunlitPgpool Global Development Group · Pgpool-IIvia NVD
Pgpool-II vulnerabilities (CVEs) · VulnSea