CVE-2026-92871
Received Received - Intake

NULL Pointer Dereference in Pgpool-II Watchdog

Vulnerability report for CVE-2026-92871, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: JPCERT/CC

Description

A NULL pointer dereference vulnerability exists in Pgpool-II, which may allow an unauthenticated attacker to cause abnormal termination of the watchdog process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pgpool pgpool *-*-*-*-*-*-*

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a NULL pointer dereference issue in Pgpool-II. It allows an unauthenticated attacker to cause the watchdog process to terminate abnormally by exploiting a flaw where the program attempts to access a memory location that does not exist.

Detection Guidance

Detection of this NULL pointer dereference vulnerability in Pgpool-II may require monitoring for abnormal watchdog process terminations. Check Pgpool-II logs for watchdog-related crashes or errors. Use commands like 'pgpool -n' to run in foreground mode for real-time monitoring or 'systemctl status pgpool' to check service stability. Ensure watchdog process logs are enabled in pgpool.conf for detailed diagnostics.

Impact Analysis

The impact includes potential denial of service as the watchdog process crashes, disrupting database connection pooling and high availability features. This could lead to database service interruptions for applications relying on Pgpool-II.

Compliance Impact

The vulnerability causes abnormal termination of the watchdog process due to a NULL pointer dereference, which may lead to service disruption or instability. This could impact compliance by failing to maintain availability or integrity of data processing systems, potentially violating requirements under GDPR (availability principle) or HIPAA (security and integrity of PHI).

Mitigation Strategies

Update Pgpool-II to the latest patched version to address the NULL pointer dereference vulnerability in the watchdog process.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92871. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart