CVE-2025-2291: Debian Linux

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired password

Affected products

  • Debian Debian Linux: version 11.0 only
  • Pgbouncer Pgbouncer: before 1.24.1 (fixed in 1.24.1)

Published 2025-04-16. Last modified 2026-06-17.