Pgbouncer
2 CVEs tracked since 2017. Since May 2017, none of them reached CISA KEV.
Pgbouncer CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2017-05 | 2 | 0 |
Products
The products that kept showing up in Pgbouncer's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 10 most recently published vulnerabilities affecting Pgbouncer.
- CVE-2026-6667PgBouncer missing authorization check in KILL_CLIENT admin command4.3
- CVE-2026-6666PgBouncer crash in kill_pool_logins_server_error5.9
- CVE-2026-6665PgBouncer buffer overflow in SCRAM8.1
- CVE-2026-6664PgBouncer integer overflow in PgBouncer network packet parsing7.5
- CVE-2025-12819Untrusted search path in auth_query connection in PgBouncer7.5
- CVE-2025-2291PgBouncer default auth_query does not take Postgres password expiry into account8.1
- CVE-2021-3672A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to ...5.6
- CVE-2021-3935When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate v...8.1
- CVE-2015-4054PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.7.5
- CVE-2015-6817PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.8.1
The record
- Peak rank
- #160 in May 2017
- Busiest month shown
- May 2017, 2 CVEs
- Months with a KEV entry
- 0 since May 2017
- Monthly snapshots
- 1 since 2017