{"id":"BIT-proxysql-2026-48773","summary":"ProxySQL pre-auth heap overflow in MySQL and PostgreSQL first-packet handling","details":"ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol first-read paths. A remote unauthenticated client can declare an oversized first packet length, and ProxySQL passes that attacker-controlled length directly to `recv()` while writing into a fixed 32 KB input queue. Version 3.0.9 patches the issue.","aliases":["CVE-2026-48773","GHSA-58ww-865x-grpr"],"modified":"2026-09-08T08:48:18.631428242Z","published":"2026-08-17T05:52:41.749Z","database_specific":{"severity":"Critical","cpes":["cpe:2.3:a:proxysql:proxysql:*:*:*:*:*:*:*:*"]},"references":[{"type":"ARTICLE","url":"https://github.com/sysown/proxysql/releases/tag/v3.0.9"},{"type":"ADVISORY","url":"https://github.com/sysown/proxysql/security/advisories/GHSA-58ww-865x-grpr"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48773"}],"affected":[{"package":{"name":"proxysql","ecosystem":"Bitnami","purl":"pkg:bitnami/proxysql"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.18"},{"fixed":"3.0.9"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/proxysql/BIT-proxysql-2026-48773.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}