Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 released.

From: Pgpool Global Development Group via PostgreSQL Announce <announce-noreply(at)postgresql(dot)org>
To: PostgreSQL Announce <pgsql-announce(at)lists(dot)postgresql(dot)org>
Subject: Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 released.
Date: 2026-10-01 12:05:44
Message-ID: 179085634482.1026193.2929315449388442328@wrigleys.postgresql.org
Views: Whole Thread | Raw Message | Download mbox | Resend email
Thread:
Lists: pgsql-announce

# What is Pgpool-II?

Pgpool-II is a tool to add useful features to PostgreSQL, including:

* connection pooling
* load balancing
* automatic failover and [more](https://www.pgpool.net/).

# Minor releases

Pgpool Global Development Group is pleased to announce the availability of following versions of Pgpool-II:

* 4.7.3
* 4.6.8
* 4.5.13
* 4.4.18
* 4.3.21

These releases include security fixes.

* A vulnerability in watchdog message processing during failover in Pgpool-II allows an attacker to write an arbitrary 32-bit value to an arbitrary memory address by sending a malformed message. (CVE-2026-92867)

* When a client connects to Pgpool-II using certificate authentication, Pgpool-II does not properly handle NUL bytes (\0) in the domain name in the Common Name (CN) field of the client's X.509 certificate. This vulnerability allows a malicious client to connect to the Pgpool-II server as another user without a password. (CVE-2026-92868)

* A vulnerability in watchdog message processing in Pgpool-II allows an attacker to overwrite memory beyond the boundaries of fixed-size arrays by sending a malformed message. (CVE-2026-92869)

* A vulnerability in the handling of failover messages by watchdog in Pgpool-II allows writes of arbitrary-length data to corrupt the stack and crash a Pgpool-II process. (CVE-2026-92870)

* A NULL pointer dereference vulnerability exists in watchdog inter-node authentication in Pgpool-II. When an authentication key is configured, crafted watchdog messages that omit authentication information are not handled correctly. (CVE-2026-92871)

* An information disclosure vulnerability exists in the heartbeat receiver process of Pgpool-II. (CVE-2026-92872)

* A vulnerability in watchdog promotion processing in Pgpool-II allows an attacker to bypass authentication key checks and promote a watchdog node of their choice to leader. (CVE-2026-92873)

For more details please see the [release notes](https://www.pgpool.net/docs/latest/en/html/release.html).

You can download [the source code and RPMs](https://pgpool.net/mediawiki/index.php/Downloads).

Browse pgsql-announce by date

  From Date Subject
Next Message IVM Development Group via PostgreSQL Announce 2026-10-05 01:15:14 pg_ivm 1.16 released
Previous Message Dasha via PostgreSQL Announce 2026-09-29 07:21:58 Dasha 1.8: index recommendations, I/O analysis, schema checks and log insights