Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pgbouncer

First CVE: Nov 18, 2012Active for: 14 yearsTotal CVEs: 11
46.8
VTI Score
High

PgBouncer is a lightweight connection pooler for PostgreSQL that occupies a critical middleware position between applications and databases, sitting directly in the data path of many deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity; the recurring weakness classes—NULL-pointer dereferences, improper authentication, certificate validation flaws, and input-handling issues including SQL injection and cross-site scripting—reflect the authentication gateway and SQL-parsing demands of a pooler handling untrusted client connections. Defenders should treat PgBouncer updates as high-priority given its role in database access control; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pgbouncer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 18, 2012
13 years ago
Most Recent CVE
May 9, 2026
76 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-6665CRITICAL
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend th
May 9, 20269.838NONO
CVE-2026-6664HIGH
An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBoun
May 9, 20267.532NONO
CVE-2025-2291CRITICAL
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired p
Apr 16, 20259.830NONO
CVE-2026-6666HIGH
A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQLSTATE field.
May 9, 20267.529NONO
CVE-2025-12819HIGH
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious
Dec 3, 20258.129NONO
CVE-2021-3935HIGH
When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of
Nov 22, 20218.127NONO
CVE-2015-4054HIGH
PgBouncer before 1.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by sending a password packet before a startup packet.
May 23, 20177.524NONO
CVE-2026-6667MEDIUM
PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requ
May 9, 20264.323NONO
CVE-2021-3672MEDIUM
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might pot
Nov 23, 20215.622NONO
CVE-2015-6817HIGH
PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.
May 23, 20178.121NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
27%
55%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (90.9%)
Unknown1 (9.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (54.5%)
High4 (36.4%)
Unknown1 (9.1%)
User Interaction
None10 (90.9%)
Unknown1 (9.1%)
Required0 (0.0%)
Privileges Required
Low1 (9.1%)
High0 (0.0%)
None9 (81.8%)
Unknown1 (9.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pgbouncer.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pgbouncer — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pgbouncer's Products

View all 4 CNAs →

Top CWEs