# Pgpool-II releases fixes for authentication bypass and memory corruption

_Published Thursday, October 1, 2026 at 9:18 AM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

The Pgpool Global Development Group released security fixes for Pgpool-II, a tool used with PostgreSQL. The fixes address seven vulnerabilities involving certificate authentication and the watchdog processes that coordinate failover between nodes.

One flaw lets a malicious client authenticate as another user without a password through improperly handled NUL bytes in a certificate's Common Name field. Another allows an attacker to bypass authentication-key checks and promote a chosen watchdog node to leader.

Other flaws permit memory corruption, process crashes or information disclosure through watchdog messages and heartbeat processing. Source code and RPM packages are available for download.

## Sources

- [PostgreSQL news](https://www.postgresql.org/about/news/pgpool-ii-473-468-4513-4418-and-4321-released-3390/)

---
Canonical: https://techandbusiness.org/newswire/BDv5L1gmHC0ppINMSCwaBU
Published: 2026-10-01T13:18:30.931Z
Story chronology: 2026-10-01T00:00:00.000Z
Retrieved: 2026-10-01T15:20:24.421Z
Publisher: Tech & Business (techandbusiness.org)
