Pgbouncer
11 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Pgbouncer, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.
Pgbouncer CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 4 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 11 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- High7
- Medium4
Latest CVEs
The 11 most recently published vulnerabilities affecting Pgbouncer.
- CVE-2026-6667PgBouncer missing authorization check in KILL_CLIENT admin command4.3
- CVE-2026-6666PgBouncer crash in kill_pool_logins_server_error5.9
- CVE-2026-6665PgBouncer buffer overflow in SCRAM8.1
- CVE-2026-6664PgBouncer integer overflow in PgBouncer network packet parsing7.5
- CVE-2025-12819Untrusted search path in auth_query connection in PgBouncer7.5
- CVE-2025-2291PgBouncer default auth_query does not take Postgres password expiry into account8.1
- CVE-2021-3672A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to ...5.6
- CVE-2021-3935When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate v...8.1
- CVE-2015-4054PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.7.5
- CVE-2015-6817PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.8.1
- CVE-2012-4575The add_database function in objects.c in the pgbouncer pooler 1.5.2 for PostgreSQL allows remote attackers to cause a denial of service (daemon outage) via a long database name in a request.5.0
Product grouping is registry-driven, with AI assist and human review. How it works