PT-2026-97388 · Pgbouncer · Pgbouncer

CVE-2026-19888

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PgBouncer versions prior to 1.25.3
Description An issue exists in the SCRAM (Salted Challenge Response Authentication Mechanism) client-final-message parser. The parser fails to validate a mandatory attribute, which can lead to a NULL pointer dereference when a required value remains unset despite the parser reporting success. A remote unauthenticated attacker can exploit this by sending a malformed message, causing the process to crash. Since the software serves all clients from a single process, this results in a denial of service that terminates all pooled connections.
Recommendations Update to version 1.25.3 or later.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15219
CVE-2026-19888

Affected Products

Pgbouncer