Vulnerabilities
Vulnerable Software
Pgbouncer:  >> Pgbouncer  >> 1.25.1  Security Vulnerabilities
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow.
CVSS Score
8.1
EPSS Score
0.0
Published
2026-05-09
A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQLSTATE field.
CVSS Score
5.9
EPSS Score
0.0
Published
2026-05-09
PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization) could run this command. It would have been correct to allow only users listed in the admin_users parameter.
CVSS Score
4.3
EPSS Score
0.0
Published
2026-05-09
An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malformed SCRAM authentication packet.
CVSS Score
7.5
EPSS Score
0.0
Published
2026-05-09


Contact Us

Shodan ® - All rights reserved