CVE-2025-12819: Pgbouncer
High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 allows an unauthenticated attacker to execute arbitrary SQL during authentication via a malicious search_path parameter in the StartupMessage.
Affected products
- Pgbouncer Pgbouncer: before 1.25.1 (fixed in 1.25.1)
Published 2025-12-03. Last modified 2026-06-17.