CVE-2025-46801 Details
Description
Pgpool-II provided by PgPool Global Development Group contains an authentication bypass by primary weakness vulnerability. if the vulnerability is exploited, an attacker may be able to log in to the system as an arbitrary user, allowing them to read or tamper with data in the database, and/or disable the database.
A vulnerability in Pgpool-II that allows authentication bypass, enabling attackers to log in as any user. This issue affects Pgpool-II versions 4.6.0, 4.5.0 through 4.5.6, 4.4.0 through 4.4.11, 4.3.0 through 4.3.14, 4.2.0 through 4.2.21, and all versions in the 4.1 and 4.0 series. The vulnerability arises in systems where specific authentication configurations are met, potentially leading to unauthorized access and manipulation of database information or disruption of database services.
Users are advised to upgrade to Pgpool-II versions 4.6.1, 4.5.7, 4.4.12, 4.3.15 or 4.2.22. For versions 4.0 and 4.1, no updates are available as these series are no longer supported.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 19, 2025CISA-ADP
Assessed May 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2025/10/msg00014.html | CVE | |
| https://jvn.jp/en/jp/JVN06238225/ | [email protected] | AdvisoryRemedy |
| https://www.pgpool.net/mediawiki/index.php/Main_Page#News | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-305 | Authentication Bypass by Primary Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Pgpool-II | 4.6.0 (semver) ~4.5 ~4.4 ~4.3 ~4.2 ~4.1 ~4.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| May 19, 2025 | New CVE Received | [email protected] |
Volerion