CVE-2026-48773 - Critical RCE in Proxysql. Pre-auth heap memory corruption via oversized packet. CVSS 9.8. Patch to v3.0.9 immediately. #CVE #infosec #Proxysql

https://www.valtersit.com/cve/CVE-2026-48773/

CVE-2026-48773 | Proxysql | Valters IT Hub

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerab...

Valters IT Hub
ProxySQL (2.0.18 – 3.0.8) hit by CRITICAL CVE-2026-48773: pre-auth heap memory corruption (CWE-787) allows remote unauthenticated attackers to trigger out-of-bounds write. Upgrade to 3.0.9 ASAP. https://radar.offseq.com/threat/cve-2026-48773-cwe-787-out-of-bounds-write-in-syso-7cef27326cf25a33 #OffSeq #ProxySQL #CVE202648773 #infosec
CVE-2026-48772 (CRITICAL): ProxySQL 2.0.0 – 3.0.8 lets attackers spoof source IPs via PROXY protocol v1, bypassing routing & ACLs. Upgrade to 3.0.9 or later. Restrict frontend port access. Details: https://radar.offseq.com/threat/cve-2026-48772-cwe-348-use-of-less-trusted-source--40b83fbf2f9ef184 #OffSeq #ProxySQL #CVE202648772 #Security
ProxySQL ⚙️ joins MariaDB Foundation 🦭 as Silver Sponsor! https://mariadb.org/psql-joins-mariadb-foundation/ #proxysql #mariabd
Testing the newly implemented #MariaDB #Galera Cluster in dbdeployer! Great job #proxysql team 🦭🦭🦭 ⚙️🏕️ https://proxysql.github.io/dbdeployer/providers/galera/

...
* MySQL is at risk at #Oracle.
* MySQL is not dead but in "maintenance mode".
* #Alibaba has more developers working on MySQL than Oracle.
* Why PostgreSQL is winning: Extensions!

Companies seen at this Summit: #Percona, #MariaDB, Oracle, #AWS, #Ubuntu/#Canonical, #WordPress, booking.com, #ProxySQL, and many other huge players in the eco-system.

During lunch I had nice talks with Aurélien LEQUOY: CEO of Istosia and developer of PmaControl for #MySQL and #MariaDB (https://github.com/PmaControl/PmaControl) and René Canao CEO of #ProxySQL (for #PostgreSQL and #MySQL).
GitHub - PmaControl/PmaControl: MySQL / MariaDB : Tools / Administration / Monitoring / Dashbord / Purge / Backup

MySQL / MariaDB : Tools / Administration / Monitoring / Dashbord / Purge / Backup - PmaControl/PmaControl

GitHub
It’s now René’s turn to shine on stage at #MySQLBrConf2025 🇧🇷 #proxysql
Here you have me, configuring my server to use #ProxySQL in New Year's Eve for lack of anything better to do
Here you have me, configuring my server to use #ProxySQL in New Year's Eve for lack of anything better to do
Bluesky

Bluesky Social