Home/Product/pgbouncer
Product

pgbouncer

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-6667
< 1.25.2
PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with acces
4.3MEDIUM
CVE-2026-6666
< 1.25.2
A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQ
5.9MEDIUM
CVE-2026-6665
< 1.25.2
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the
8.1HIGH
CVE-2026-6664
< 1.25.2
An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. A
7.5HIGH
CVE-2025-12819
< 1.25.1
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute ar
7.5HIGH
CVE-2025-2291
< 1.24.1
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allo
8.1HIGH
CVE-2021-3672
<= 1.17.0
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can
5.6MEDIUM
CVE-2021-3935
< 1.16.1
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a co
8.1HIGH
CVE-2015-6817
all versions
PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unk
8.1HIGH
CVE-2015-4054
<= 1.5.4
PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a pass
7.5HIGH
CVE-2012-4575
all versions
The add_database function in objects.c in the pgbouncer pooler 1.5.2 for PostgreSQL allows remote attackers to cause a denial of s
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin