Pgbouncer
This hub aggregates every CVE we track for Pgbouncer, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
Databasesother
11
CVEs tracked
0
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7MEDIUM4
Monthly trend
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
1
0
0
0
0
4
0
0
0
2024-092026-08
Latest CVEs
The 11 most recently published vulnerabilities affecting Pgbouncer.
- CVE-2026-6667PgBouncer missing authorization check in KILL_CLIENT admin command4.3
- CVE-2026-6666PgBouncer crash in kill_pool_logins_server_error5.9
- CVE-2026-6665PgBouncer buffer overflow in SCRAM8.1
- CVE-2026-6664PgBouncer integer overflow in PgBouncer network packet parsing7.5
- CVE-2025-12819Untrusted search path in auth_query connection in PgBouncer7.5
- CVE-2025-2291PgBouncer default auth_query does not take Postgres password expiry into account8.1
- CVE-2021-3672A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to ...5.6
- CVE-2021-3935When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate v...8.1
- CVE-2015-4054PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.7.5
- CVE-2015-6817PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.8.1
- CVE-2012-4575The add_database function in objects.c in the pgbouncer pooler 1.5.2 for PostgreSQL allows remote attackers to cause a denial of service (daemon outage) via a long database name in a request.5.0
Product normalization is registry-driven with AI assist and human review. How it works