pgbouncer
Databasesoss-project
Top products
Latest CVEs
The 10 most recently published vulnerabilities affecting pgbouncer.
- CVE-2026-6667PgBouncer missing authorization check in KILL_CLIENT admin command4.3
- CVE-2026-6666PgBouncer crash in kill_pool_logins_server_error5.9
- CVE-2026-6665PgBouncer buffer overflow in SCRAM8.1
- CVE-2026-6664PgBouncer integer overflow in PgBouncer network packet parsing7.5
- CVE-2025-12819Untrusted search path in auth_query connection in PgBouncer7.5
- CVE-2025-2291PgBouncer default auth_query does not take Postgres password expiry into account8.1
- CVE-2021-3672A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to ...5.6
- CVE-2021-3935When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate v...8.1
- CVE-2015-4054PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.7.5
- CVE-2015-6817PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.8.1