CVE-2026-48773

CRITICAL

ProxySQL pre-auth heap overflow in MySQL and PostgreSQL first-packet handling

Title source: cna
STIX 2.1

Description

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol first-read paths. A remote unauthenticated client can declare an oversized first packet length, and ProxySQL passes that attacker-controlled length directly to `recv()` while writing into a fixed 32 KB input queue. Version 3.0.9 patches the issue.

References (2)

Core 2
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/sysown/proxysql/releases/tag/v3.0.9

Scores

CVSS v3 9.8
EPSS 0.0065
EPSS Percentile 47.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-787
Status published
Products (1)
sysown/proxysql >= 2.0.18, < 3.0.9
Published Jun 19, 2026
Tracked Since Jun 20, 2026