PT-2025-21640 · Pgpool-Ii+3 · Pgpool-Ii+3

Published

2025-05-15

·

Updated

2025-10-16

·

CVE-2025-46801

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Pgpool-II versions 4.0.x through 4.6.0
Description: The issue allows attackers to bypass authentication. There is no information provided about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations: For versions 4.0.x through 4.6.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ALT-PU-2025-6814
ALT-PU-2025-6816
ALT-PU-2025-6817
ALT-PU-2025-6818
ALT-PU-2025-6819
ALT-PU-2025-7189
ALT-PU-2025-7191
ALT-PU-2025-7192
ALT-PU-2025-7193
ALT-PU-2025-7194
BDU:2025-07452
CVE-2025-46801
DLA-4334-1
DSA-5974-1

Affected Products

Alt Linux
Debian
Pgpool-Ii
Red Os