PT-2026-97389 · Pgbouncer · Pgbouncer

CVE-2026-6668

·

Published

2026-09-23

·

Updated

2026-10-03

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions PgBouncer versions prior to 1.25.3
Description An integer overflow exists in the packet buffer growth logic. When processing sufficiently large input, the buffer size computation overflows, causing a growth loop that cannot terminate. Since the software serves all clients from a single process, this condition saturates a CPU core and stalls every pooled connection, leading to a denial of service. This issue can be triggered by both unauthenticated and authenticated remote attackers.
Recommendations Update to version 1.25.3 or later.

Fix

Infinite Loop

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15220
CVE-2026-6668

Affected Products

Pgbouncer