Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 2 min read

Pgpool-II 3.5.x through 4.2.x: the branches that will not be patched

Pgpool-II 3.5.x through 4.2.x: the branches that will not be patched JVN#22475874 lists seven CVEs in Pgpool-II and gives fixed releases for five branches. Every release in the 3.5.x through 4.2.x series appears in the

Pgpool-II 3.5.x through 4.2.x: the branches that will not be patched

JVN#22475874 lists seven CVEs in Pgpool-II and gives fixed releases for five branches. Every release in the 3.5.x through 4.2.x series appears in the affected ranges, and that support has ended. Operators still running those versions have no patch to install, and the advisory recommends upgrading to a maintained release instead.

What the advisory says about the older branches

The notice names Pgpool-II 4.7.0 to 4.7.2, 4.6.0 to 4.6.7, 4.5.0 to 4.5.12, 4.4.0 to 4.4.17 and 4.3.0 to 4.3.20 as affected, and adds that all versions from the 3.5.x series through the 4.2.x series are affected as well. Six of the seven CVEs cover that whole range. CVE-2026-92868 has a narrower range that starts at 4.0.x.

Fixed releases exist only for the maintained branches: 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21. The advisory states plainly that support for versions 3.5 through 4.2 has ended and that no further fixes will be released.

The seven defects that carry over

The affected older branches inherit the full set. CVE-2026-92867 is an out-of-bounds write with a CVSS v3 score of 8.8, and the advisory links it to arbitrary code execution. CVE-2026-92868 is improper certificate validation and allows client certificate authentication bypass. CVE-2026-92869 is another out-of-bounds write, CVE-2026-92870 is a stack-based buffer overflow, CVE-2026-92871 is a NULL pointer dereference that terminates the watchdog process, CVE-2026-92872 leaks cluster information through logs, and CVE-2026-92873 promotes an arbitrary watchdog node to the leader role.

None of these will receive a backport. A cluster on 4.2.x keeps all seven until the branch is replaced.

Why old poolers survive so long

Pgpool-II sits between applications and PostgreSQL, so replacing it touches the data path that everything else depends on. That dependency gives an upgrade a blast radius, and the blast radius is the reason old versions accumulate. Declustering before the upgrade, moving to a standby pooler first, or scheduling a window with the application owners are the usual ways to reduce the risk.

Exposure of the retired branches

A ZoomEye query for app="Pgpool-II" returned 101 internet-visible instances on 29 September 2026. The CVE-specific query vul.cve="CVE-2026-92868" returned zero. ZoomEye does not report which release each instance runs, so the 101 figure neither confirms nor excludes the retired branches.

Impact of staying on an unsupported branch

The immediate risk is the seven CVEs. The longer-term risk is that the branch stops receiving any fix, so the next advisory will add to the list rather than replace it. For CVE-2026-92867 that matters most, because an out-of-bounds write with arbitrary code execution potential inside a credential-holding process is the kind of flaw that gets exploited after public disclosure rather than before.

Remediation

There is no patch for 3.5.x through 4.2.x. The advisory recommends upgrading to the latest version, and the maintained targets are 4.7.3, 4.6.8, 4.5.13, 4.4.18 and 4.3.21. A branch upgrade normally involves configuration changes as well as a version change, so the work should be planned rather than applied as a hotfix.

Until the branch changes, restricting who can reach the pooler and confirming that the watchdog peer network is not visible to application subnets are the controls available without vendor guidance.

References

JVN#22475874: Multiple vulnerabilities in Pgpool-II

Pgpool Global Development Group

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.