CVE-2025-2291: Debian Linux
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password
Affected products
Published 2025-04-16. Last modified 2026-06-17.