PT-2026-97389 · Pgbouncer · Pgbouncer
CVE-2026-6668
·
Published
2026-09-23
·
Updated
2026-10-03
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
PgBouncer versions prior to 1.25.3
Description
An integer overflow exists in the packet buffer growth logic. When processing sufficiently large input, the buffer size computation overflows, causing a growth loop that cannot terminate. Since the software serves all clients from a single process, this condition saturates a CPU core and stalls every pooled connection, leading to a denial of service. This issue can be triggered by both unauthenticated and authenticated remote attackers.
Recommendations
Update to version 1.25.3 or later.
Fix
Infinite Loop
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pgbouncer