CVE-2026-6665: Pgbouncer
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM server-final-message with a long nonce can trigger a stack overflow.
Affected products
- Pgbouncer Pgbouncer: before 1.25.2 (fixed in 1.25.2)
Published 2026-05-09. Last modified 2026-07-24.