Pgpool-II Software Patched for Seven Vulnerabilities
The Pgpool Global Development Group issued critical updates following the discovery of seven distinct security flaws.
Updated on Sept. 29, 2026 in Cybersecurity

The Pgpool Global Development Group has released software updates to address seven vulnerabilities identified in Pgpool-II. These security flaws were disclosed to the group by researcher Emond Papegaaij of Topicus Security.
Why it matters
The patches mitigate multiple security risks present within the database connection pooling software, which serves critical infrastructure for many database clusters. The update cycle marks a significant transition point as support for versions 3.5 through 4.2 has officially ended.
The advisory addresses seven distinct vulnerabilities tracked as CVE-2026-92867 through CVE-2026-92873. Users operating on versions prior to 4.3 are no longer supported and must upgrade to the latest version to remain secure.
The players
Pgpool Global Development Group
An open-source collective responsible for maintaining the Pgpool-II database middleware and its associated security updates.
Emond Papegaaij
A security researcher at Topicus Security who identified and reported the seven vulnerabilities.
JPCERT/CC
A Japanese coordination organization that monitors global cybersecurity threats and collaborates on vulnerability disclosures.
The details
The vulnerabilities were uncovered by Emond Papegaaij of Topicus Security and subsequently verified by the Pgpool Global Development Group and JPCERT/CC, a Japanese coordination center for computer emergency response. Pgpool-II functions as a middleware—a software layer that connects database servers and applications—designed to manage connection pooling, replication, and load balancing. The released patches adjust internal handling mechanisms that previously allowed for these seven distinct security weaknesses.
Timeline
September 29, 2026: The vulnerability advisory was officially published.
The Tech Race
This release follows standard industry practices for managing legacy technical debt by ending support for older software iterations. It aligns with broader trends where security maintenance forces a transition from outdated versions toward a unified, current codebase.
Administrators running Pgpool-II versions 3.5 through 4.2 must upgrade to the latest version, as these versions have officially reached their end-of-life. Users should check their current deployment against the new release to ensure their database connection middleware is protected.
The takeaway
Maintaining database security requires constant vigilance against newly identified CVEs that target middleware infrastructure. Administrators should audit their current software versions immediately to ensure they are not operating on the unsupported 3.5 through 4.2 branches.
Further reading
For more information on infrastructure hardening and vulnerability management, visit Cybersecurity.
Source note: This article includes information reported by Jvn.






