Vulnerabilities in Pgpool Global Development Group
11 resultsVexday analysis
Pgpool registra 7 vulnerabilidades na base, todas publicadas nos últimos 90 dias, indicando exposição recente a riscos. Nenhuma está sob exploração ativa conhecida (KEV) e não há críticas de severidade máxima, mas a predominância de CWE-787 (buffer overflow) sinaliza deficiências estruturais no tratamento de memória que demandam atenção imediata.
CVE-2018-16203—PgpoolAdmin 4.0 and earlier allows remote attackers to bypass the login authentication and obtain the administrative privilege of the PostgrEPSS 1.7%CVE-2025-46801CRITICALPgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerabilEPSS 0.9%CVE-2023-22332MEDIUMInformation disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 seriEPSS 0.7%CVE-2024-45624HIGHExposure of sensitive information due to incompatible policies issue exists in Pgpool-II. If a database user accesses a query cache, table dEPSS 0.5%CVE-2026-92867HIGHAn out-of-bounds write vulnerability exists in Pgpool-II , which may allow an authenticated attacker to cause abnormal process termination oEPSS 0.3%CVE-2026-92870HIGHA stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termiEPSS 0.3%CVE-2026-92873MEDIUMPgpool-II contains an incorrect implementation of an authentication algorithm, which may allow an unauthenticated attacker to promote an arbEPSS 0.3%CVE-2026-92871HIGHA NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of tEPSS 0.3%CVE-2026-92869HIGHAn out-of-bounds write vulnerability exists in Pgpool-II, which may allow an authenticated attacker to cause abnormal process termination.EPSS 0.3%CVE-2026-92872MEDIUMPgpool-II inserts sensitive information into log file, which may allow an authenticated attacker to obtain the cluster information.EPSS 0.2%CVE-2026-92868MEDIUMAn improper certificate validation vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to bypass client certificaEPSS 0.2%