Heap Memory Corruption in ProxySQL Affects MySQL and PostgreSQL Users
CVE-2026-48773

9.8CRITICAL

Key Information:

Vendor

Sysown

Status
Vendor
CVE Published:
19 June 2026

What is CVE-2026-48773?

A vulnerability in ProxySQL affects versions from 2.0.18 to 3.0.8, allowing remote unauthenticated clients to exploit the MySQL and PostgreSQL protocols. An attacker can send an oversized first packet length, leading to heap memory corruption by injecting attacker-controlled values into a fixed size input queue. This vulnerability highlights the critical need to update to version 3.0.9, which mitigates this potential security risk.

Affected Version(s)

proxysql >= 2.0.18, < 3.0.9

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.