CVE-2026-92870
Received Received - Intake

Stack-Based Buffer Overflow in Pgpool-II

Vulnerability report for CVE-2026-92870, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: JPCERT/CC

Description

A stack-based buffer overflow vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal process termination.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pgpool pgpool *-*-*-*-*-*-*

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-121 A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-92870 is a stack-based buffer overflow vulnerability in Pgpool-II. It allows an unauthenticated attacker to cause abnormal process termination by exploiting improper memory handling.

Detection Guidance

Detecting this vulnerability requires checking the installed version of Pgpool-II against the affected versions. Use commands like 'pgpool --version' or check package managers (e.g., 'rpm -qa | grep pgpool' or 'dpkg -l | grep pgpool'). Monitor logs for abnormal process terminations or crashes.

Impact Analysis

This vulnerability may lead to denial of service by crashing Pgpool-II processes. In severe cases, it could enable arbitrary code execution, potentially compromising system integrity.

Compliance Impact

A successful exploit could disrupt data availability, violating GDPR's integrity principle or HIPAA's access controls. This may lead to compliance breaches requiring incident reporting.

Mitigation Strategies

Immediately update Pgpool-II to the latest patched versions (4.7.3, 4.6.8, 4.5.13, 4.4.18, or 4.3.21). Disable unnecessary network exposure and restrict access to Pgpool-II ports. Review and enforce strict client certificate validation if applicable.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92870. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart