CVE-2025-12819
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
HIGH · CVSS 7.5
EPSS 0.00185
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0