PT-2026-97388 · Pgbouncer · Pgbouncer
CVE-2026-19888
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
PgBouncer versions prior to 1.25.3
Description
An issue exists in the SCRAM (Salted Challenge Response Authentication Mechanism) client-final-message parser. The parser fails to validate a mandatory attribute, which can lead to a NULL pointer dereference when a required value remains unset despite the parser reporting success. A remote unauthenticated attacker can exploit this by sending a malformed message, causing the process to crash. Since the software serves all clients from a single process, this results in a denial of service that terminates all pooled connections.
Recommendations
Update to version 1.25.3 or later.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pgbouncer