CVE Tools

Pgbouncer

2 CVEs tracked since 2017. Since May 2017, none of them reached CISA KEV.

Pgbouncer CVEs per month

May 2017 to May 2017. Point at a month, or focus the strip and use the arrow keys.
Pgbouncer CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2017-0520

Products

The products that kept showing up in Pgbouncer's monthly top three, with their CVEs summed over those months.

  1. Pgbouncer21 month

Latest CVEs

The 10 most recently published vulnerabilities affecting Pgbouncer.

  1. CVE-2026-6667PgBouncer missing authorization check in KILL_CLIENT admin command4.3
  2. CVE-2026-6666PgBouncer crash in kill_pool_logins_server_error5.9
  3. CVE-2026-6665PgBouncer buffer overflow in SCRAM8.1
  4. CVE-2026-6664PgBouncer integer overflow in PgBouncer network packet parsing7.5
  5. CVE-2025-12819Untrusted search path in auth_query connection in PgBouncer7.5
  6. CVE-2025-2291PgBouncer default auth_query does not take Postgres password expiry into account8.1
  7. CVE-2021-3672A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to ...5.6
  8. CVE-2021-3935When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate v...8.1
  9. CVE-2015-4054PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.7.5
  10. CVE-2015-6817PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.8.1

The record

Peak rank
#160 in May 2017
Busiest month shown
May 2017, 2 CVEs
Months with a KEV entry
0 since May 2017
Monthly snapshots
1 since 2017
Pgbouncer's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store