CVE-2025-12819: Pgbouncer

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.

Affected products

  • Pgbouncer Pgbouncer: before 1.25.1 (fixed in 1.25.1)

Published 2025-12-03. Last modified 2026-06-17.