# Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 released.

DevFeed: [Pgpool-II 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21 released.](<https://devfeed.tech/articles/pgpool-ii-4-7-3-4-6-8-4-5-13-4-4-18-and-4-3-21-released-63123.md>)

Original publisher: [Read original article](<https://www.postgresql.org/about/news/pgpool-ii-473-468-4513-4418-and-4321-released-3390/>)

Author: Pgpool Global Development Group

Published: 2026-10-01T00:00:00Z

Content type: release

Language: en

Sources: [PostgreSQL news](<https://devfeed.tech/sources/postgresql-news.md>)

Topics: [releases](<https://devfeed.tech/topics/releases.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Load Balancing](<https://devfeed.tech/topics/load-balancing.md>), [certificates](<https://devfeed.tech/topics/certificates.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [fixed](<https://devfeed.tech/tags/fixed.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

Pgpool Global Development Group released Pgpool-II versions 4.7.3, 4.6.8, 4.5.13, 4.4.18, and 4.3.21 with security fixes. The notice describes vulnerabilities involving watchdog message processing, certificate authentication, memory corruption, information disclosure, and promotion authentication checks.

## Source excerpt

What is Pgpool-II? Pgpool-II is a tool to add useful features to PostgreSQL, including: connection pooling load balancing automatic failover and more. Minor releases Pgpool Global Development Group is pleased to announce the availability of following versions of Pgpool-II: 4.7.3 4.6.8 4.5.13 4.4.18 4.3.21 These releases include security fixes. A vulnerability in watchdog message processing during failover in Pgpool-II allows an attacker to write an arbitrary 32-bit value to an arbitrary memory address by sending a malformed message. (CVE-2026-92867) When a client connects to Pgpool-II using certificate authentication, Pgpool-II does not properly handle NUL bytes (\0) in the domain name in the Common Name (CN) field of the client's X.509 certificate. This vulnerability allows a malicious client to connect to the Pgpool-II server as another user without a password. (CVE-2026-92868) A vulnerability in watchdog message processing in Pgpool-II allows an attacker to overwrite memory beyond the boundaries of fixed-size arrays by sending a malformed message. (CVE-2026-92869) A vulnerability in the handling of failover messages by watchdog in Pgpool-II allows writes of arbitrary-length data to corrupt the stack and crash a Pgpool-II process. (CVE-2026-92870) A NULL pointer dereference vulnerability exists in watchdog inter-node authentication in Pgpool-II. When an authentication key is configured, crafted watchdog messages that omit authentication information are not handled correctly. (CVE-2026-92871) An information disclosure vulnerability exists in the heartbeat receiver process of Pgpool-II. (CVE-2026-92872) A vulnerability in watchdog promotion processing in Pgpool-II allows an attacker to bypass authentication key checks and promote a watchdog node of their choice to leader. (CVE-2026-92873) For more details please see the release notes. You can download the source code and RPMs.