CVE-2026-48772(proxysql / proxysql)

LOWCVSS 10.0 · CRITICAL

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame as a well-formed PROXY protocol header. The HAProxy PROXY protocol v1 specification says that when the protocol token is `UNKNOWN`, the receiver MUST ignore any address fields that follow it, because the proxy has declared it cannot determine the client identity. ProxySQL parses those address fields anyway via `sscanf` and writes the spoofed source address into the session's `addr.addr` field. From there it flows directly into the query-rule matcher, where the `client_addr` predicate decides routing and ACL. When `mysql-proxy_protocol_networks = '*'` (the default), any TCP peer can send a PP1 frame and choose any source IP claim. With that, any `mysql_query_rules` row pinned to a `client_addr` value is forgeable: the attacker writes the address they want to match into the PP1 line, and ProxySQL routes their query as if it came from that address. In practice this is a routing and ACL bypass. Real deployments use `client_addr` for read-write splitting (internal apps go to the primary, public traffic to read replicas), per-app schema pinning, and query-filter rules (DDL allowed only from admin CIDR, public queries blocked from dangerous patterns). An attacker that can reach the frontend port can forge their way into any of those routes. Version 3.0.9 patches this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-348CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • proxysql

Affected systems

Vendors
Products
proxysql

Deep dive

Full discourse8 posts
  • Aretiq.AI@AretiqAI
    Disclosure

    ARETIQ Daily Vulnerability Bulletin — June 19, 2026 🔴 CRITICAL: CVE-2026-55255 (langflow-ai/langflow) AAS 13.1 🔴 CRITICAL: CVE-2026-48772 (sysown/proxysql) AAS 12.8 🔴 CRITICAL: CVE-2026-48773 (sysown/proxysql) AAS 12.4 15 vulnerabilities — CRITICAL: 3, HIGH: 12 Full bulletin: https://aretiq.ai/bulletins/2026-06-19/

    Post summary

    The bulletin announces three critical CVEs for langflow‑ai/langflow and sysown/proxysql with severity ratings, but provides no technical details, exploitation evidence, or patch information.

    01030126
    190 followersView on X
  • Kaitan ID Security@KaitanSecurity
    PoC

    ⚠️ CVE of the week — CVE-2026-48772 (CVSS 10.0) · NVD/NIST 💣 Exploit available https://sec.kaitan.id/cves/CVE-2026-48772?utm_source=x&utm_campaign=tuesday_highlight 📬 Weekly recap → https://sec.kaitan.id/blog #cybersecurity #cve #vulnmanagement #kaitanid https://t.co/kEgD7vCjzf

    Post summary

    The tweet highlights CVE-2026-48772 and notes that an exploit or proof‑of‑concept is available, providing a link for further details.

    0000043
    82 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: Critical vulnerabilities in #ProxySQL allow remote attackers to corrupt heap memory and bypass ACLs. #CVE-2026-48772 CVSS(3.1): 10.0 | #CVE-2026-48773 CVSS(3.1): 9.8. Read the advisory https://ccb.belgium.be/advisories/warning-acl-bypass-and-heap-memory-corruption-proxysql-can-be-exploited-compromise and #Patch #Patch #Patch

    Post summary

    The advisory announces two critical ProxySQL vulnerabilities—heap memory corruption and ACL bypass—with high CVSS scores, and directs users to apply the vendor patch.

    00000374
    7.2K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-48772 - Critical #Unauthorized Access in #ProxySQL. #CVSS 10.0. Vulnerable versions 2.0.0-3.0.8 accept malformed PROXY UNKNOWN headers, bypassing authentication. #CVEAlert #devops #devsecops FREE FIX available: https://www.valtersit.com/cve/CVE-2026-48772

    Post summary

    The post highlights a critical vulnerability in ProxySQL and offers a free fix, providing technical details but no evidence of active exploitation or exploit code.

    0000062
    959 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-48772 PROXY Protocol Spoofing and ACL Bypass in ProxySQL Versions 2.0.0-3.0.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48772

    Post summary

    The text announces a new CVE affecting ProxySQL 2.0.0‑3.0.8, noting proxy protocol spoofing and ACL bypass, but does not provide a PoC, exploit, or patch details.

    0000069
    4.1K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 ProxySQL Critical vuln (CVE-2026-48772) &lt;= 3.0.8 - easy IP spoofing via PROXY UNKNOWN
 → full bypass of client_addr rules &amp; ACLs Fix: upgrade to 3.0.9+ now! #ProxySQL #MySQL #CVE

    Post summary

    The post announces a critical ProxySQL vulnerability (CVE-2026-48772) describing its IP spoofing flaw and provides a patch recommendation to upgrade to version 3.0.9 or newer.

    0000069
    219 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-48772 ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN

    Post summary

    The tweet announces CVE‑2026‑48772 affecting ProxySQL 2.0.0–3.0.8, noting that the MySQL frontend accepts the `PROXY UNKNOWN` command.

    0000026
    82 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48772 ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN &lt;addr&gt; &lt;ad… https://www.cve.org/CVERecord?id=CVE-2026-48772

    Post summary

    The snippet announces CVE‑2026‑48772 in ProxySQL, listing affected versions and a brief vulnerability description, but provides no exploit, patch, or PoC information.

    00000265
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appproxysqlproxysql---

Explore more