Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-48773

Опубликовано: 19 июн. 2026
Источник: debian
EPSS Низкий

Описание

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol first-read paths. A remote unauthenticated client can declare an oversized first packet length, and ProxySQL passes that attacker-controlled length directly to `recv()` while writing into a fixed 32 KB input queue. Version 3.0.9 patches the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
proxysqlitppackage

EPSS

Процентиль: 28%
0.00358
Низкий

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol first-read paths. A remote unauthenticated client can declare an oversized first packet length, and ProxySQL passes that attacker-controlled length directly to `recv()` while writing into a fixed 32 KB input queue. Version 3.0.9 patches the issue.

CVSS3: 9.8
fstec
2 месяца назад

Уязвимость реализации протоколов MySQL и PostgreSQL прокси-сервера для баз данных ProxySQL, позволяющая нарушителю вызвать повреждение памяти

EPSS

Процентиль: 28%
0.00358
Низкий