CVE-2026-6665
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the conten
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow.
HIGH · CVSS 8.1
EPSS 0.0002
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0