Description
A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.
Published: 2026-09-30
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Unauthenticated Attack
Action: Immediate Upgrade
AI Analysis

Impact

A stack-based buffer overflow in Pgpool-II can be triggered by an unauthenticated user, causing the process to terminate unexpectedly. The flaw stems from insufficient bounds checking on user-supplied data, aligning with CWE‑121. The primary consequence is denial of service, as the failed process must be restarted to restore normal database proxy functionality. There is no indication in the current data that arbitrary code execution or data exfiltration is possible, but a terminated process could lead to broader system instability if not handled promptly.

Affected Systems

All versions of Pgpool-II distributed by the Pgpool Global Development Group are vulnerable, as no specific version range is provided in the advisory. Organizations relying on Pgpool-II for PostgreSQL connection pooling should review installed versions and plan an upgrade accordingly.

Risk and Exploitability

The vulnerability has a CVSS score of 8.7, indicating a high severity level. EPSS data is not available, and the issue is not referenced in the CISA KEV catalog. Based on the description, the likely attack vector is remote network access to the Pgpool-II service, where an unauthenticated client can send crafted input to trigger the overflow. The absence of exploit probability data means that while the vulnerability is severe, the likelihood of active exploitation is uncertain, yet the potential impact warrants proactive mitigation.

Generated by OpenCVE AI on September 30, 2026 at 12:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Pgpool‑II release that contains the stack buffer overflow fix.
  • Restrict inbound traffic to the Pgpool‑II port(s) using firewall rules, allowing only trusted hosts or IP ranges.
  • Monitor Pgpool‑II logs and system process metrics for unexpected termination events and configure alerts for abnormal exits.

Generated by OpenCVE AI on September 30, 2026 at 12:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Title Stack-based Buffer Overflow in Pgpool‑II Allows Unauthenticated Process Termination

Wed, 30 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.
Weaknesses CWE-121
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-30T07:21:24.156Z

Reserved: 2026-09-17T06:31:54.744Z

Link: CVE-2026-92870

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T08:16:35.040

Modified: 2026-09-30T08:16:35.040

Link: CVE-2026-92870

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T12:15:17Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow