Pgpool
Pgpool-ii: vulnerabilidades y CVE
Pgpool-ii tiene 10 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses7
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-92873 | Media (6.9) | 0.31% | — | 30 sept 2026 | Pgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbitrary watchdog node to the leader node. |
| CVE-2026-92872 | Media (5.3) | 0.18% | — | 30 sept 2026 | Pgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information. |
| CVE-2026-92871 | Alta (8.7) | 0.29% | — | 30 sept 2026 | A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process. |
| CVE-2026-92870 | Alta (8.7) | 0.32% | — | 30 sept 2026 | A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination. |
| CVE-2026-92869 | Alta (7.1) | 0.25% | — | 30 sept 2026 | An out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination. |
| CVE-2026-92868 | Media (6.9) | 0.15% | — | 30 sept 2026 | An improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificate authentication. |
| CVE-2026-92867 | Alta (8.7) | 0.34% | — | 30 sept 2026 | An out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination or arbitrary code execution. |
| CVE-2025-46801 | Crítica (9.3) | 0.91% | — | 19 may 2025 | Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an… |
| CVE-2024-45624 | Alta (7.5) | 0.53% | — | 12 sept 2024 | Exposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table data unauthorized for the user may be retrieved. |
| CVE-2023-22332 | Media (6.5) | 0.70% | — | 30 ene 2023 | Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.