| From: | Pgpool Global Development Group via PostgreSQL Announce <announce-noreply(at)postgresql(dot)org> |
|---|---|
| To: | PostgreSQL Announce <pgsql-announce(at)lists(dot)postgresql(dot)org> |
| Subject: | Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 released. |
| Date: | 2026-10-01 12:05:44 |
| Message-ID: | 179085634482.1026193.2929315449388442328@wrigleys.postgresql.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-announce |
# What is Pgpool-II?
Pgpool-II is a tool to add useful features to PostgreSQL, including:
* connection pooling
* load balancing
* automatic failover and [more](https://www.pgpool.net/).
# Minor releases
Pgpool Global Development Group is pleased to announce the availability of following versions of Pgpool-II:
* 4.7.3
* 4.6.8
* 4.5.13
* 4.4.18
* 4.3.21
These releases include security fixes.
* A vulnerability in watchdog message processing during failover in Pgpool-II allows an attacker to write an arbitrary 32-bit value to an arbitrary memory address by sending a malformed message. (CVE-2026-92867)
* When a client connects to Pgpool-II using certificate authentication, Pgpool-II does not properly handle NUL bytes (\0) in the domain name in the Common Name (CN) field of the client's X.509 certificate. This vulnerability allows a malicious client to connect to the Pgpool-II server as another user without a password. (CVE-2026-92868)
* A vulnerability in watchdog message processing in Pgpool-II allows an attacker to overwrite memory beyond the boundaries of fixed-size arrays by sending a malformed message. (CVE-2026-92869)
* A vulnerability in the handling of failover messages by watchdog in Pgpool-II allows writes of arbitrary-length data to corrupt the stack and crash a Pgpool-II process. (CVE-2026-92870)
* A NULL pointer dereference vulnerability exists in watchdog inter-node authentication in Pgpool-II. When an authentication key is configured, crafted watchdog messages that omit authentication information are not handled correctly. (CVE-2026-92871)
* An information disclosure vulnerability exists in the heartbeat receiver process of Pgpool-II. (CVE-2026-92872)
* A vulnerability in watchdog promotion processing in Pgpool-II allows an attacker to bypass authentication key checks and promote a watchdog node of their choice to leader. (CVE-2026-92873)
For more details please see the [release notes](https://www.pgpool.net/docs/latest/en/html/release.html).
You can download [the source code and RPMs](https://pgpool.net/mediawiki/index.php/Downloads).
| From | Date | Subject | |
|---|---|---|---|
| Next Message | IVM Development Group via PostgreSQL Announce | 2026-10-05 01:15:14 | pg_ivm 1.16 released |
| Previous Message | Dasha via PostgreSQL Announce | 2026-09-29 07:21:58 | Dasha 1.8: index recommendations, I/O analysis, schema checks and log insights |